Vulnerability Description
Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Johnsoncontrols | Qolsys Iq Panel 4 Firmware | < 4.4.2 |
| Johnsoncontrols | Qolsys Iq Panel 4 | - |
| Johnsoncontrols | Qolsys Iq4 Hub Firmware | < 4.4.2 |
| Johnsoncontrols | Qolsys Iq4 Hub | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-039-01Third Party AdvisoryUS Government Resource
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesProduct
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-039-01Third Party AdvisoryUS Government Resource
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesProduct
FAQ
What is CVE-2024-0242?
CVE-2024-0242 is a vulnerability with a CVSS score of 7.3 (HIGH). Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.
How severe is CVE-2024-0242?
CVE-2024-0242 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0242?
Check the references section above for vendor advisories and patch information. Affected products include: Johnsoncontrols Qolsys Iq Panel 4 Firmware, Johnsoncontrols Qolsys Iq Panel 4, Johnsoncontrols Qolsys Iq4 Hub Firmware, Johnsoncontrols Qolsys Iq4 Hub.