CVE-2024-0242: Unauthorized access to settings in Qolsys IQ Panel 4 and IQ4 Hub
Published Feb 8, 2024
·Updated
Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.
Affected Software
4 affected components
All of the following
Johnsoncontrols Qolsys Iq Panel 4 Firmware<4.4.2
Johnsoncontrols Qolsys Iq Panel 4
All of the following
Johnsoncontrols Qolsys Iq4 Hub Firmware<4.4.2
Johnsoncontrols Qolsys Iq4 Hub
Remediation
Information
Upgrade IQ Panel 4 to version 4.4.2.
Information
Upgrade IQ4 Hub to version 4.4.2.
Information
The firmware can be updated remotely to all available devices in the field.
Information
The firmware update can also be manually loaded by applying the patch tag “iqpanel4.4.2” on the device after navigating to its firmware update page.
Event History
Feb 8, 2024
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0242?
CVE-2024-0242 is considered a moderate severity vulnerability due to the potential for unauthorized access to settings.
2
How do I fix CVE-2024-0242?
To fix CVE-2024-0242, upgrade the IQ Panel4 or IQ4 Hub software to version 4.4.2 or later.
3
What software is affected by CVE-2024-0242?
CVE-2024-0242 affects the IQ Panel4 and IQ4 Hub software prior to version 4.4.2.
4
Can CVE-2024-0242 be exploited remotely?
Yes, CVE-2024-0242 can potentially be exploited remotely if the software is not updated.
5
What are the potential consequences of CVE-2024-0242?
The potential consequences of CVE-2024-0242 include unauthorized access to security settings, which may compromise system integrity.