CVE-2026-5434: CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory in Honeywell International Inc. Control Network Module (CNM)
CVE-2026-5434 is a vulnerability in Honeywell International Inc.'s Control Network Module (CNM) that involves the insertion of sensitive information into an unintended directory. This could allow an attacker to probe system files and potentially gain unintended access to protected data. The affected CNM versions include 100.1, 101.1, 110.1, and 110.2. Honeywell recommends updating to the most recent version 200.1 to address this issue. The vulnerability has a medium severity score of 5.9 and does not have any known exploits in the wild.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-5434 (CWE-538) affects Honeywell's Control Network Module (CNM) versions 100.1, 101.1, 110.1, and 110.2. It involves the insertion of sensitive information into directories that are externally accessible, which could be probed by an attacker to access protected data. The CVSS v3.1 score is 5.9, indicating medium severity, with network attack vector, high attack complexity, no privileges required, no user interaction, and high confidentiality impact but no integrity or availability impact. Honeywell advises updating to version 200.1 to mitigate this vulnerability. No official patch or remediation level is explicitly stated beyond this recommendation, and no known exploits have been reported.
Potential Impact
An attacker could potentially access sensitive information that was improperly stored in an externally accessible directory, leading to unauthorized disclosure of protected data. The vulnerability does not affect system integrity or availability. The medium CVSS score reflects the moderate risk due to the high attack complexity and lack of required privileges or user interaction.
Mitigation Recommendations
Honeywell recommends updating the Control Network Module (CNM) to the most recent version 200.1. This update is the primary remediation step to address the vulnerability. Since no official patch or temporary fix details are provided, applying the vendor-recommended update is the advised action. There are no indications that the vulnerability is already mitigated or that no action is required.
CVE-2026-5434: CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory in Honeywell International Inc. Control Network Module (CNM)
Description
CVE-2026-5434 is a vulnerability in Honeywell International Inc.'s Control Network Module (CNM) that involves the insertion of sensitive information into an unintended directory. This could allow an attacker to probe system files and potentially gain unintended access to protected data. The affected CNM versions include 100.1, 101.1, 110.1, and 110.2. Honeywell recommends updating to the most recent version 200.1 to address this issue. The vulnerability has a medium severity score of 5.9 and does not have any known exploits in the wild.
CVSS v3.1
Score 5.9medium
Affected software
Honeywell International Inc.
Control Network Module (CNM)
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-5434 (CWE-538) affects Honeywell's Control Network Module (CNM) versions 100.1, 101.1, 110.1, and 110.2. It involves the insertion of sensitive information into directories that are externally accessible, which could be probed by an attacker to access protected data. The CVSS v3.1 score is 5.9, indicating medium severity, with network attack vector, high attack complexity, no privileges required, no user interaction, and high confidentiality impact but no integrity or availability impact. Honeywell advises updating to version 200.1 to mitigate this vulnerability. No official patch or remediation level is explicitly stated beyond this recommendation, and no known exploits have been reported.
Potential Impact
An attacker could potentially access sensitive information that was improperly stored in an externally accessible directory, leading to unauthorized disclosure of protected data. The vulnerability does not affect system integrity or availability. The medium CVSS score reflects the moderate risk due to the high attack complexity and lack of required privileges or user interaction.
Mitigation Recommendations
Honeywell recommends updating the Control Network Module (CNM) to the most recent version 200.1. This update is the primary remediation step to address the vulnerability. Since no official patch or temporary fix details are provided, applying the vendor-recommended update is the advised action. There are no indications that the vulnerability is already mitigated or that no action is required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Honeywell
- Date Reserved
- 2026-04-02T16:12:23.800Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a0eee5b7b8e1438d0bb6ccd
Added to database: 05/21/2026, 11:36:59 UTC
Last enriched: 08/06/2026, 17:32:53 UTC
Last updated: 09/11/2026, 00:58:13 UTC
Views: 173
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.