CVE-2023-4804

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_compressor:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_acuair:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_condenser\/vessel:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_evaporator:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_engine_room:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_interface:-:*:*:*:*:*:*:*

History

16 Nov 2023, 17:45

Type Values Removed Values Added
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - Third Party Advisory, US Government Resource
CPE cpe:2.3:h:johnsoncontrols:quantum_hd_unity_compressor:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_engine_room:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_condenser\/vessel:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_evaporator:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_interface:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_acuair:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE NVD-CWE-Other
First Time Johnsoncontrols quantum Hd Unity Engine Room
Johnsoncontrols quantum Hd Unity Engine Room Firmware
Johnsoncontrols quantum Hd Unity Interface
Johnsoncontrols quantum Hd Unity Acuair Firmware
Johnsoncontrols quantum Hd Unity Compressor
Johnsoncontrols quantum Hd Unity Evaporator Firmware
Johnsoncontrols
Johnsoncontrols quantum Hd Unity Interface Firmware
Johnsoncontrols quantum Hd Unity Acuair
Johnsoncontrols quantum Hd Unity Evaporator
Johnsoncontrols quantum Hd Unity Condenser\/vessel Firmware
Johnsoncontrols quantum Hd Unity Compressor Firmware
Johnsoncontrols quantum Hd Unity Condenser\/vessel

10 Nov 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-10 23:15

Updated : 2023-12-10 15:26


NVD link : CVE-2023-4804

Mitre link : CVE-2023-4804

CVE.ORG link : CVE-2023-4804


JSON object : View

Products Affected

johnsoncontrols

  • quantum_hd_unity_engine_room
  • quantum_hd_unity_evaporator_firmware
  • quantum_hd_unity_compressor_firmware
  • quantum_hd_unity_compressor
  • quantum_hd_unity_interface
  • quantum_hd_unity_acuair_firmware
  • quantum_hd_unity_condenser\/vessel_firmware
  • quantum_hd_unity_evaporator
  • quantum_hd_unity_engine_room_firmware
  • quantum_hd_unity_condenser\/vessel
  • quantum_hd_unity_interface_firmware
  • quantum_hd_unity_acuair
CWE
NVD-CWE-Other CWE-489

Active Debug Code