Carrier Global Corporation
Self-Reporting Analysis
Of all the CVEs published by Carrier Global Corporation as a CNA, 37.5% affect products that Carrier Global Corporation develops as a vendor.
Of all the CVEs published that affect products developed by Carrier Global Corporation, 52.9% are self-published by Carrier Global Corporation as a CNA.
Trends Over Time
The number and severity of CVEs published by Carrier Global Corporation over time
Top CVEs
All CVEs published by Carrier Global Corporation as a CNA, regardless of affected vendor or product.
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31479CRITICAL An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnera | Jun 6, 2022 | 9.8 | 32 | NO | NO |
CVE-2024-2420CRITICAL LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypas | May 30, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-5539CRITICAL The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions an | Nov 27, 2025 | 9.2 | 28 | NO | NO |
CVE-2024-8527HIGH Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions. | Nov 19, 2025 | 8.6 | 28 | NO | NO |
CVE-2025-9495HIGH The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTM | Sep 23, 2025 | 8.7 | 28 | NO | NO |
CVE-2024-8525CRITICAL An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execution via a crafted HTTP POST re | Nov 21, 2024 | 10.0 | 28 | NO | NO |
CVE-2025-0658HIGH A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol
causes the device to crash. The device enters a fault state; after a reset,
a second packet can | Nov 27, 2025 | 8.7 | 27 | NO | NO |
CVE-2025-0657HIGH A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver
version drv_gen5_106-01-2380, allows
malformed packets to be sent through BACnet MS/TP network causing the | Nov 27, 2025 | 8.8 | 27 | NO | NO |
CVE-2022-31486HIGH An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mer | Jun 6, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-31483HIGH An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability | Jun 6, 2022 | 8.8 | 27 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (24 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Carrier Global Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Carrier Global Corporation as a CNA — matched by CVE ID, not by organization name.