Honeywell IQ4x BMS Controller
A critical authentication vulnerability (CVSS 10.0) in Honeywell IQ4x BMS Controller firmware versions 3.50 through 4.36_build_4.3.7.9 allows unauthorized attackers to access management settings, control components, and cause denial-of-service without authentication. Honeywell has not yet released a patch and recommends network isolation and defensive measures until remediation is available.
Summary
A critical authentication vulnerability (CVSS 10.0) in Honeywell IQ4x BMS Controller firmware versions 3.50 through 4.36_build_4.3.7.9 allows unauthorized attackers to access management settings, control components, and cause denial-of-service without authentication. Honeywell has not yet released a patch and recommends network isolation and defensive measures until remediation is available.
Indicators of Compromise
- cve — CWE-306