CVE-2023-4804

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_compressor:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_acuair:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_condenser\/vessel:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_evaporator:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_engine_room:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_interface:-:*:*:*:*:*:*:*

History

16 Nov 2023, 17:45

Type Values Removed Values Added
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-313-01 - Third Party Advisory, US Government Resource
CPE cpe:2.3:h:johnsoncontrols:quantum_hd_unity_compressor:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_condenser\/vessel_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_evaporator:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_interface:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_acuair:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_compressor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_evaporator_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_engine_room:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_interface_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_acuair_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:quantum_hd_unity_condenser\/vessel:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:quantum_hd_unity_engine_room_firmware:*:*:*:*:*:*:*:*
First Time Johnsoncontrols quantum Hd Unity Engine Room Firmware
Johnsoncontrols quantum Hd Unity Compressor Firmware
Johnsoncontrols quantum Hd Unity Condenser\/vessel
Johnsoncontrols
Johnsoncontrols quantum Hd Unity Condenser\/vessel Firmware
Johnsoncontrols quantum Hd Unity Compressor
Johnsoncontrols quantum Hd Unity Acuair
Johnsoncontrols quantum Hd Unity Interface Firmware
Johnsoncontrols quantum Hd Unity Evaporator
Johnsoncontrols quantum Hd Unity Engine Room
Johnsoncontrols quantum Hd Unity Interface
Johnsoncontrols quantum Hd Unity Evaporator Firmware
Johnsoncontrols quantum Hd Unity Acuair Firmware
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

10 Nov 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-10 23:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-4804

Mitre link : CVE-2023-4804

CVE.ORG link : CVE-2023-4804


JSON object : View

Products Affected

johnsoncontrols

  • quantum_hd_unity_condenser\/vessel
  • quantum_hd_unity_interface
  • quantum_hd_unity_evaporator_firmware
  • quantum_hd_unity_compressor
  • quantum_hd_unity_acuair
  • quantum_hd_unity_interface_firmware
  • quantum_hd_unity_condenser\/vessel_firmware
  • quantum_hd_unity_engine_room_firmware
  • quantum_hd_unity_compressor_firmware
  • quantum_hd_unity_evaporator
  • quantum_hd_unity_engine_room
  • quantum_hd_unity_acuair_firmware
CWE
NVD-CWE-Other CWE-489

Active Debug Code