Executive brief
Honeywell IQ MultiAccess, a professional access control system used for managing building security and personnel entry, is affected by a vulnerability in how it verifies file signatures. An attacker with local access to the system could exploit a timing-based flaw to replace legitimate software files with malicious ones during the download process. This could allow an attacker to compromise the security system's integrity, potentially leading to unauthorized access or operational disruptions.
Technical details
Honeywell IQ MultiAccess (up to version 28) is vulnerable to a Time-of-Check Time-of-Use (TOCTOU) race condition (CWE-367) during the digital signature verification process for downloaded files. An attacker with local, low-privileged access can exploit the window between the file's verification and its execution/installation to replace the legitimate file with a malicious payload. This bypasses the integrity checks intended to ensure only authentic Honeywell software is run. Honeywell recommends upgrading to V27 SP1 or V28 SP1 to mitigate this issue.
Affected products
- Honeywell IQ MultiAccess All versions prior to and including version 28
Timeline
- 2026-06-29: disclosed
- 2026-06-29: advisory