CVE-2026-5434
Received
Received - Intake
Path Traversal in Honeywell Control Network Module
Vulnerability report for CVE-2026-5434, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-05-21
Last updated on: 2026-07-27
Assigner: Honeywell International Inc.
Description
Description
Honeywell Control
Network Module (CNM) contains
insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing
system files, potentially resulting in unintended
access to protected data.
Honeywell
recommends updating to the most recent version of this product, service or
offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| honeywell | control_network_module_firmware | From 100.1 (inc) to 110.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-538 | The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. |