Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the knowledge of other users, altering the controller's function capabilities. The changed configuration is not updated in the User Interface, which creates an inconsistency between the configuration display and the actual configuration on the controller. After the configuration change, remediation requires reverting to the correct configuration, requiring either physical or remote access depending on the configuration that was altered.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Honeywell Alerton Ascent Control Module 安全漏洞
Vulnerability Description
Honeywell Alerton Ascent Control Module是USAHoneywell公司的一款高性能、符合 BACnet 的集成楼宇控制器和路由器。可以支持 BACnet/以太网、BACnet/IP 和 BACnet/MSTP。 Honeywell Alerton Ascent Control Module (ACM) 2022-05-04 及之前版本存在安全漏洞,攻击者利用该漏洞可以发送一个精心制作的数据包来改变控制器的配置,从而改变控制器的功能。
CVSS Information
N/A
Vulnerability Type
N/A