Carrier Global Corporation

First CVE: Jun 6, 2022Active for: 4 years
24
CVEs Published
More CVEs Published than 45% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
8.2
Avg CVSS Score
Higher Avg CVSS Score than 89% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Carrier Global Corporation as a CNA, 37.5% affect products that Carrier Global Corporation develops as a vendor.

37.5%
62.5%
Self-reported: 9Third-party: 15

Of all the CVEs published that affect products developed by Carrier Global Corporation, 52.9% are self-published by Carrier Global Corporation as a CNA.

52.9%
47.1%
Self-published: 9Published by other CNAs: 8

Trends Over Time

The number and severity of CVEs published by Carrier Global Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 6, 2022
4 years ago
Most Recent CVE
Jan 22, 2026
183 days ago

Top CVEs

All CVEs published by Carrier Global Corporation as a CNA, regardless of affected vendor or product.

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnera
Jun 6, 20229.832NONO
LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypas
May 30, 20249.829NONO
The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions an
Nov 27, 20259.228NONO
Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions.
Nov 19, 20258.628NONO
The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTM
Sep 23, 20258.728NONO
An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execution via a crafted HTTP POST re
Nov 21, 202410.028NONO
A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The device enters a fault state; after a reset, a second packet can
Nov 27, 20258.727NONO
A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed packets to be sent through BACnet MS/TP network causing the
Nov 27, 20258.827NONO
An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mer
Jun 6, 20228.827NONO
An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability
Jun 6, 20228.827NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA24 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local4 (16.7%)
Network18 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (91.7%)
High2 (8.3%)
Unknown0 (0.0%)
User Interaction
None21 (87.5%)
Unknown0 (0.0%)
Required1 (4.2%)
Privileges Required
Low5 (20.8%)
High1 (4.2%)
None18 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Carrier Global Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Carrier Global Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs