Impact
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. This improper storage can lead to confidentiality loss, as attackers may gain access to protected information by probing system files. The weakness corresponds to CWE‑538, indicating that data is stored in a location that is not properly protected or segregated.
Affected Systems
The affected product is Honeywell International Inc.’s Control Network Module (CNM). Affected versions include 100.1, 101.1, 110.1, and 110.2. The vendor recommends updating to version 200.1. Administrators should determine if their CNM installation is one of the vulnerable versions.
Risk and Exploitability
The CVSS score of 5.9 reflects moderate risk. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV, indicating no widespread exploitation to date. The likely attack vector is probing of system files to locate where sensitive data has been inadvertently stored; this inference is based on the description that an attacker could exploit the weakness through probing system files. The absence of documented exploitation suggests the likelihood is uncertain, but the potential impact warrants proactive remediation.
OpenCVE Enrichment