CVE-2023-4804: Johnsoncontrols Quantum Hd Unity Acuair Firmware
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
Affected products
- Johnsoncontrols Quantum Hd Unity Acuair Firmware: from 11.00, before 11.12 (fixed in 11.12); from 12.00, before 12.12 (fixed in 12.12)
- Johnsoncontrols Quantum Hd Unity Compressor Firmware: from 11.00, before 11.22 (fixed in 11.22); from 12.00, before 12.22 (fixed in 12.22)
- Johnsoncontrols Quantum Hd Unity Condenser/vessel Firmware: from 11.00, before 11.11 (fixed in 11.11); from 12.00, before 12.11 (fixed in 12.11)
- Johnsoncontrols Quantum Hd Unity Engine Room Firmware: from 11.00, before 11.11 (fixed in 11.11); from 12.00, before 12.11 (fixed in 12.11)
- Johnsoncontrols Quantum Hd Unity Evaporator Firmware: from 11.00, before 11.11 (fixed in 11.11); from 12.00, before 12.11 (fixed in 12.11)
- Johnsoncontrols Quantum Hd Unity Interface Firmware: from 11.00, before 11.11 (fixed in 11.11); from 12.00, before 12.11 (fixed in 12.11)
Published 2023-11-10. Last modified 2026-06-17.