CVE-2026-5434
Received Received - Intake

Path Traversal in Honeywell Control Network Module

Vulnerability report for CVE-2026-5434, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-05-21

Last updated on: 2026-07-27

Assigner: Honeywell International Inc.

Description

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data. Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-05-21
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-05-21
EPSS Evaluated
2026-06-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
honeywell control_network_module_firmware From 100.1 (inc) to 110.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-538 The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability exists in the Honeywell Control Network Module (CNM) where sensitive information can be inserted into an unintended directory. An attacker could exploit this by probing system files, which may lead to unintended access to protected data.

Impact Analysis

This vulnerability could allow an attacker to gain unintended access to sensitive or protected data by exploiting the insertion of sensitive information into unintended directories. This could compromise the confidentiality of your data.

Compliance Impact

The vulnerability in Honeywell Control Network Module (CNM) involves insertion of sensitive information into an unintended directory, which could lead to unintended access to protected data. This type of data exposure could potentially impact compliance with data protection regulations such as GDPR and HIPAA, which require safeguarding sensitive information and preventing unauthorized access.

However, the provided context and resources do not explicitly discuss the impact of this vulnerability on compliance with specific standards or regulations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5434. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart