Description
Honeywell Control
Network Module (CNM) contains
insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing
system files, potentially resulting in unintended
access to protected data.



Honeywell
recommends updating to the most recent version of this product, service or
offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
Published: 2026-05-21
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. This improper storage can lead to confidentiality loss, as attackers may gain access to protected information by probing system files. The weakness corresponds to CWE‑538, indicating that data is stored in a location that is not properly protected or segregated.

Affected Systems

The affected product is Honeywell International Inc.’s Control Network Module (CNM). Affected versions include 100.1, 101.1, 110.1, and 110.2. The vendor recommends updating to version 200.1. Administrators should determine if their CNM installation is one of the vulnerable versions.

Risk and Exploitability

The CVSS score of 5.9 reflects moderate risk. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV, indicating no widespread exploitation to date. The likely attack vector is probing of system files to locate where sensitive data has been inadvertently stored; this inference is based on the description that an attacker could exploit the weakness through probing system files. The absence of documented exploitation suggests the likelihood is uncertain, but the potential impact warrants proactive remediation.

Generated by OpenCVE AI on August 3, 2026 at 07:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for Honeywell Control Network Module (CNM) that addresses improper data placement.
  • Configure the CNM to enforce directory boundaries for sensitive data, ensuring that such data is stored only in designated secure locations.
  • Implement strict file system permissions and audit user privileges so that only authorized accounts can write to or read from the protected directories.
  • Perform regular scans of system directories for unintended storage of sensitive information and set up alerts for anomalous file access patterns.

Generated by OpenCVE AI on August 3, 2026 at 07:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data. Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
Title Improper storage of sensitive information
Weaknesses CWE-538
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 02 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Title Improper storage of sensitive information
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-538
CPEs cpe:2.3:h:honeywell:control_network_module:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:control_network_module_firmware:*:*:*:*:*:*:*:*
Vendors & Products Honeywell control Network Module
Honeywell control Network Module Firmware
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 02 Jun 2026 14:15:00 +0000

Type Values Removed Values Added
Description Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Tue, 26 May 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Honeywell control Network Module
Honeywell control Network Module Firmware
CPEs cpe:2.3:h:honeywell:control_network_module:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:control_network_module_firmware:*:*:*:*:*:*:*:*
Vendors & Products Honeywell control Network Module
Honeywell control Network Module Firmware

Fri, 22 May 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Honeywell
Honeywell control Network Module (cnm)
Vendors & Products Honeywell
Honeywell control Network Module (cnm)

Thu, 21 May 2026 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data.
Title Improper storage of sensitive information
Weaknesses CWE-538
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Honeywell Control Network Module (cnm)
cve-icon MITRE

Status: PUBLISHED

Assigner: Honeywell

Published:

Updated: 2026-07-30T16:51:02.885Z

Reserved: 2026-04-02T16:12:23.800Z

Link: CVE-2026-5434

cve-icon Vulnrichment

Updated: 2026-05-21T12:06:36.288Z

cve-icon NVD

Status : Rejected

Published: 2026-05-21T09:16:30.410

Modified: 2026-06-02T14:17:05.110

Link: CVE-2026-5434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T07:45:17Z

Weaknesses
  • CWE-538

    Insertion of Sensitive Information into Externally-Accessible File or Directory