CVE-2026-3611
The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module.
Leer descripción completaMostrar menos
Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configuration and administration.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.99%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access90 % - Impacto secundario
T1531Account Access Removalimpact80 % - Impacto secundario
T1565.001Stored Data Manipulationimpact85 %
Acceso sin autenticación a interfaz web remota (AV:N/PR:N/UI:N) en configuración por defecto de controlador Honeywell IQ4x. Impacto: creación de cuentas administrativas (T1078), manipulación de configuración (T1565.001) y bloqueo de operadores legítimos (T1531).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (5)
CWE
- CWE-306
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-3611",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-3611",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-03-13T18:02:46.954644Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 10,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Honeywell",
"product": "IQ4E",
"versions": [
{
"status": "affected",
"version": "v3.50_3.44",
"versionType": "custom",
"lessThanOrEqual": "4.36 (build 4.3.7.9)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Honeywell",
"product": "IQ412",
"versions": [
{
"status": "affected",
"version": "v3.50_3.44",
"versionType": "custom",
"lessThanOrEqual": "4.36 (build 4.3.7.9)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Honeywell",
"product": "IQ422",
"versions": [
{
"status": "affected",
"version": "v3.50_3.44",
"versionType": "custom",
"lessThanOrEqual": "4.36 (build 4.3.7.9)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Honeywell",
"product": "IQ4NC",
"versions": [
{
"status": "affected",
"version": "v3.50_3.44",
"versionType": "custom",
"lessThanOrEqual": "4.36 (build 4.3.7.9)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Honeywell",
"product": "IQ41x",
"versions": [
{
"status": "affected",
"version": "v3.50_3.44",
"versionType": "custom",
"lessThanOrEqual": "4.36 (build 4.3.7.9)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Honeywell",
"product": "IQ3",
"versions": [
{
"status": "affected",
"version": "v3.50_3.44",
"versionType": "custom",
"lessThanOrEqual": "4.36 (build 4.3.7.9)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Honeywell",
"product": "IQECO",
"versions": [
{
"status": "affected",
"version": "v3.50_3.44",
"versionType": "custom",
"lessThanOrEqual": "4.36 (build 4.3.7.9)"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-12T21:16:27.693",
"references": [
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-03.json",
"tags": [
"Issue Tracking"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-03",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.honeywell.com/us/en/contact",
"tags": [
"Product"
],
"source": "ics-cert@hq.dhs.gov"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module. Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configuration and administration."
},
{
"lang": "es",
"value": "El controlador de gestión de edificios Honeywell IQ4x expone su HMI completo basado en web sin autenticación en su configuración predeterminada de fábrica. Al no tener ningún módulo de usuario configurado, la seguridad está deshabilitada por diseño y el sistema opera bajo un contexto de Invitado del Sistema (nivel 100), otorgando privilegios de lectura/escritura a cualquier parte capaz de alcanzar la interfaz HTTP. Los controles de autenticación solo se aplican después de que se crea un usuario web a través de U.htm, lo que habilita dinámicamente el módulo de usuario. Debido a que esta función es accesible antes de la autenticación, un usuario remoto puede crear una nueva cuenta con permisos administrativos de lectura/escritura, habilitando el módulo de usuario e imponiendo la autenticación bajo credenciales controladas por el atacante. Esta acción puede bloquear eficazmente a los operadores legítimos de la configuración y administración local y basada en web."
}
],
"lastModified": "2026-06-17T10:43:52.107",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:honeywell:iq4e_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64D4FED0-F7BD-48AC-AC59-06075C86EAB9",
"versionEndExcluding": "3.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:honeywell:iq4e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1CD48C55-F8BB-45B8-9D48-14CC945D9F58"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:honeywell:iq412_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D9E71C6-E460-4F2F-81C1-48BD2FD6CA2C",
"versionEndExcluding": "3.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:honeywell:iq412:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AA5FC8F1-94F0-4848-881B-A1E6B89F790F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:honeywell:iq422_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4742F1A-D5D9-48FB-AEB7-5422F7FF066E",
"versionEndExcluding": "3.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:honeywell:iq422:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F4E33759-C75F-4802-B9C8-D5355BC9C5CA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:honeywell:iq4nc_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B0096DB-D66E-4BD9-AE99-98FBBD5D73A1",
"versionEndExcluding": "3.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:honeywell:iq4nc:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3BC9FA2A-6FDE-49EE-A204-C24ECE7113AB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:honeywell:iq41x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C8FF65E-9C63-4645-9224-97C23C782E32",
"versionEndExcluding": "3.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:honeywell:iq41x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "90EB7C01-E8E0-421A-85FD-EAE27E527C1A"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}