CVE-2023-4804

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_compressor:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_acuair:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_condenser\/vessel:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_evaporator:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_engine_room:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_interface:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 10.0
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory

16 Nov 2023, 17:45

Type Values Removed Values Added
CPE cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_interface:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_compressor:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_engine_room:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_acuair:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_evaporator:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_condenser\/vessel:-:*:*:*:*:*:*:*
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - Third Party Advisory, US Government Resource
First Time Johnsoncontrols quantum Hd Unity Condenser\/vessel Firmware
Johnsoncontrols quantum Hd Unity Interface
Johnsoncontrols quantum Hd Unity Acuair Firmware
Johnsoncontrols quantum Hd Unity Engine Room
Johnsoncontrols quantum Hd Unity Evaporator Firmware
Johnsoncontrols quantum Hd Unity Condenser\/vessel
Johnsoncontrols
Johnsoncontrols quantum Hd Unity Compressor Firmware
Johnsoncontrols quantum Hd Unity Evaporator
Johnsoncontrols quantum Hd Unity Compressor
Johnsoncontrols quantum Hd Unity Acuair
Johnsoncontrols quantum Hd Unity Interface Firmware
Johnsoncontrols quantum Hd Unity Engine Room Firmware
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

Information

Published : 2023-11-10 23:15

Updated : 2024-11-21 08:36


NVD link : CVE-2023-4804

Mitre link : CVE-2023-4804

CVE.ORG link : CVE-2023-4804


JSON object : View

Products Affected

johnsoncontrols

  • quantum_hd_unity_engine_room
  • quantum_hd_unity_interface_firmware
  • quantum_hd_unity_engine_room_firmware
  • quantum_hd_unity_acuair_firmware
  • quantum_hd_unity_condenser\/vessel
  • quantum_hd_unity_evaporator_firmware
  • quantum_hd_unity_compressor
  • quantum_hd_unity_interface
  • quantum_hd_unity_compressor_firmware
  • quantum_hd_unity_evaporator
  • quantum_hd_unity_acuair
  • quantum_hd_unity_condenser\/vessel_firmware
CWE
CWE-489

Active Debug Code

NVD-CWE-Other