CVE-2023-4804

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_compressor:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_acuair:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_condenser\/vessel:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_evaporator:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_engine_room:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_interface:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:36

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 10.0

16 Nov 2023, 17:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_condenser\/vessel:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_evaporator:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_acuair:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_compressor:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_interface:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_engine_room:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
First Time Johnsoncontrols quantum Hd Unity Engine Room Firmware
Johnsoncontrols quantum Hd Unity Compressor Firmware
Johnsoncontrols quantum Hd Unity Interface
Johnsoncontrols quantum Hd Unity Engine Room
Johnsoncontrols
Johnsoncontrols quantum Hd Unity Acuair Firmware
Johnsoncontrols quantum Hd Unity Compressor
Johnsoncontrols quantum Hd Unity Acuair
Johnsoncontrols quantum Hd Unity Condenser\/vessel Firmware
Johnsoncontrols quantum Hd Unity Evaporator
Johnsoncontrols quantum Hd Unity Evaporator Firmware
Johnsoncontrols quantum Hd Unity Interface Firmware
Johnsoncontrols quantum Hd Unity Condenser\/vessel
CWE NVD-CWE-Other
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory

10 Nov 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-10 23:15

Updated : 2024-11-21 08:36


NVD link : CVE-2023-4804

Mitre link : CVE-2023-4804

CVE.ORG link : CVE-2023-4804


JSON object : View

Products Affected

johnsoncontrols

  • quantum_hd_unity_engine_room_firmware
  • quantum_hd_unity_interface
  • quantum_hd_unity_compressor
  • quantum_hd_unity_engine_room
  • quantum_hd_unity_interface_firmware
  • quantum_hd_unity_condenser\/vessel
  • quantum_hd_unity_evaporator
  • quantum_hd_unity_evaporator_firmware
  • quantum_hd_unity_condenser\/vessel_firmware
  • quantum_hd_unity_acuair_firmware
  • quantum_hd_unity_compressor_firmware
  • quantum_hd_unity_acuair
CWE
CWE-489

Active Debug Code

NVD-CWE-Other