Back to overview

CVE-2023-4804

CRITICAL
10.0
CVSS 3.1
Description
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

Metadata

CVE ID
CVE-2023-4804
State
PUBLISHED
Assigner
jci
Reserved
2023-09-06 15:44 UTC
Published
2023-11-10 22:17 UTC
Last updated
2025-12-16 18:23 UTC
Primary CWE
CWE-489
CWE-489: Active Debug Code
Vendor / Product
Johnson Controls / Quantum HD Unity Compressor
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (6)
VendorProductPlatformVersions
Johnson Controls Quantum HD Unity AcuAir 0 < 11.12, 0 < 12.12
Johnson Controls Quantum HD Unity Compressor 0 < 11.22, 0 < 12.22
Johnson Controls Quantum HD Unity Condenser/Vessel 0 < 11.11, 0 < 12.11
Johnson Controls Quantum HD Unity Engine Room 0 < 11.11, 0 < 12.11
Johnson Controls Quantum HD Unity Evaporator 0 < 11.11, 0 < 12.11
Johnson Controls Quantum HD Unity Interface 0 < 11.11, 0 < 12.11
Weakness (CWE)
CWESourceDescription
CWE-489 cna CWE-489: Active Debug Code
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview