Improper storage of sensitive information
Summary
| CVE | CVE-2026-5434 |
|---|---|
| State | PUBLISHED |
| Assigner | Honeywell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-21 09:16:30 UTC |
| Updated | 2026-07-27 15:17:06 UTC |
| Description | Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data. Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2]. |
Risk And Classification
Primary CVSS: v3.1 5.9 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.000410000 probability, percentile 0.125730000 (date 2026-06-02)
Problem Types: CWE-538 | CWE-538 CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Honeywell International Inc. | Control Network Module CNM | affected 100.1 110.2 cpe | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.honeywell.com/us/en/product-security | [email protected] | www.honeywell.com | |
| process.honeywell.com | MITRE | process.honeywell.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Andreas Krämer, BASF Digital Solutions GmbH (en)
CNA: Martin Floeck, BASF Digital Solutions GmbH (en)
CNA: Stefan Stahl, BASF Digital Solutions GmbH (en)
There are currently no legacy QID mappings associated with this CVE.