Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability has been identified in Honeywell IQ4x building management controllers, allowing unauthenticated remote access to the system's web interface. This could permit unauthorized users to alter critical building controls, potentially disrupting operations or locking out legitimate administrators.
- Unauthenticated access to building management controls.
- Could disrupt operations or lock out administrators.
- Confirm relevance and exposure to building systems.
Attack Path
How an attacker could exploit the issue
An attacker can reach the Honeywell IQ4x controller through its web interface, which is exposed by default without any authentication. This allows an unauthenticated remote user to access the system's administrative functions. By creating a new account with full privileges, the attacker can then lock out legitimate users and gain complete control over the device.
- Unauthenticated network access required.
- Attacker creates an administrative account.
- Complete device control and lockout.
Live Threat
Current exploitation, exposure, and threat context
The Honeywell IQ4x building management controller's default configuration exposes its web interface without authentication. This allows an unauthenticated remote attacker to create an administrative account, enabling user module authentication and potentially locking out legitimate operators. No specific system data types or PII are mentioned as at risk in the provided context.
- Building management controller access.
- Remote attacker creates administrative credentials.
- Legitimate operators could lose control.
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
The Honeywell IQ4x building management controller's default configuration exposes its web interface without authentication, allowing remote attackers to establish administrative accounts and lock out legitimate users. This vulnerability resides within the operational technology (OT) infrastructure, likely managed by a combination of facilities management, IT infrastructure, and OT security teams. The immediate priority is to identify all deployed IQ4x controllers, assess their network reachability and criticality, and determine the responsible system owner for remediation planning.
- Facilities or OT infrastructure teams own the issue.
- Verify all IQ4x controller network reachability.
- Plan remediation based on identified risk.