ICSA-20-049-01
·
Published 2020-02-18
·
View on CISA ICS-CERT ↗
Honeywell INNCOM INNControl 3
CVSS 6.6
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to escalate user privileges within the INNControl application.
CVEs (1)
Remediations
- Honeywell encourages users to contact an INNCOM sales representative or authorized systems integrator to obtain information on upgrading their system(s) to the latest version. Honeywell also offers online INNCOM support. Additional information about the vulnerability can be found in the Honeywell Security Notification.
- Honeywell recommends that, subject to each user's individual assessment of the potential impact(s) of the vulnerabilities and/or recommendations on their specific operational building control network environment(s), users with potentially affected products are recommended to take the following steps to mitigate the effects of potential vulnerabilities:
- Update the software of potentially impacted systems as per the Security Notification.
- Disable unnecessary accounts and services.
- Restrict system access to authorized personnel only and follow a least privilege approach.
- Apply defense-in-depth strategies.
Affected Vendors
Honeywell
Affected Products (1)
Honeywell
·
INNControl 3
<= 3.21
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy, Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more