{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-5434",
        "assignerOrgId": "0dc86260-d7e3-4e81-ba06-3508e030ce8d",
        "state": "PUBLISHED",
        "assignerShortName": "Honeywell",
        "dateReserved": "2026-04-02T16:12:23.800Z",
        "datePublished": "2026-05-21T08:38:25.477Z",
        "dateUpdated": "2026-07-30T16:51:02.885Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "0dc86260-d7e3-4e81-ba06-3508e030ce8d",
                "shortName": "Honeywell",
                "dateUpdated": "2026-07-27T14:04:00.120Z"
            },
            "title": "Improper storage of sensitive information",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-538",
                            "description": "CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-639",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-639: Probe System Files"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Honeywell International Inc.",
                    "product": "Control Network Module (CNM)",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "100.1",
                            "lessThanOrEqual": "110.2",
                            "versionType": "cpe"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Honeywell Control\nNetwork Module (CNM) contains\ninsertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing\nsystem files, potentially resulting in unintended\naccess to protected data.\n\n\n\nHoneywell\nrecommends updating to the most recent version of this product, service or\noffering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>Honeywell Control\nNetwork Module (CNM)&nbsp;<span>contains\n</span><span>insertion of sensitive </span><span>information i</span><span>nto an unintended directory</span><span>. </span><span>An attacker could exploit this vulnerability </span><span>through</span><span> </span><span>probing\nsystem files</span><span>, </span><span>potentially resulting in </span><span>unintended\naccess to protected data</span><span>.</span></p><p>Honeywell\nrecommends updating to the most recent version of this product, service or\noffering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.honeywell.com/us/en/product-security"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "HIGH",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "availabilityImpact": "NONE",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 5.9,
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Andreas Krämer, BASF Digital Solutions GmbH",
                    "type": "finder"
                },
                {
                    "lang": "en",
                    "value": "Martin Floeck, BASF Digital Solutions GmbH",
                    "type": "finder"
                },
                {
                    "lang": "en",
                    "value": "Stefan Stahl, BASF Digital Solutions GmbH",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.2"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-05-21T12:06:31.149864Z",
                                "id": "CVE-2026-5434",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-30T16:51:02.885Z"
                }
            }
        ]
    }
}