CVE-2026-5434: Improper storage of sensitive information
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data.
Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5434?
CVE-2026-5434 has a medium severity rating of 5.9.
How do I fix CVE-2026-5434?
To address CVE-2026-5434, ensure that sensitive information is stored in the correct directories and restrict access to system files.
What type of sensitive information is at risk with CVE-2026-5434?
CVE-2026-5434 may expose protected data due to improper storage of sensitive information.
What can an attacker do by exploiting CVE-2026-5434?
An attacker could gain unintended access to sensitive information by probing vulnerable directories.
Which software is affected by CVE-2026-5434?
CVE-2026-5434 affects Honeywell Control Network Module (CNM).