Honeywell INNCOM INNControl 3
This vulnerability in INNControl 3 allows privilege escalation within the application due to improper access controls (CWE-269). An attacker with a low-privilege user account on a local or connected INNControl 3 system could escalate to higher privileges, potentially gaining unauthorized control over building automation settings. The vulnerability affects INNControl 3 version 3.21 and earlier. Honeywell has not released a patch, but recommends upgrading to the latest version through authorized representatives. No known public exploits exist for this vulnerability.
- Local access to an INNControl 3 system (physical or via remote desktop with valid user credentials)
- Low-privilege user account credentials
- System running INNControl 3 version 3.21 or earlier
Patching may require device reboot — plan for process interruption
/api/v1/advisories/b62a6205-3c91-42b5-a378-89e7b8d2ffb7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.