CVE-2024-0242: Johnsoncontrols Qolsys IQ4 Hub Firmware
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.
Affected products
- Johnsoncontrols Qolsys IQ4 Hub Firmware: before 4.4.2 (fixed in 4.4.2)
- Johnsoncontrols Qolsys Iq Panel 4 Firmware: before 4.4.2 (fixed in 4.4.2)
Published 2024-02-08. Last modified 2026-06-17.