Database/Control plane, storage & DevOps
Honeywell Alerton Visual Logic, Ascent Control Module (ACM) and Compass 1.6.5: Unauthenticated program writes
Impact
Unauthenticated program writes to the controller. Not configuration - program. An attacker on the network can push new control logic onto an Alerton controller and stop or replace the running program with no verification of who they are. This is the deepest form of BMS compromise available: the attacker is not sending a bad setpoint that an operator might notice and override, they are rewriting the control algorithm so the controller itself now does the wrong thing and reports the right thing. Applied to the controllers sequencing CRAHs or chilled water in a GPU hall, an attacker can write logic that holds fans low, ignores high-temperature alarms, or trips the plant on a delay so the failure looks like a mechanical fault. Thermal shutdown of a 40-140 kW rack row follows in minutes, and the forensics point at the HVAC contractor rather than at an intrusion. The companion issues let configuration be changed the same way, unauthenticated.
Who can reach it
A crafted packet from any host on the controller's network - no authentication exists on the programming path at all. Alerton gear sits on the building/facility VLAN, and the Alerton BACtalk ecosystem is BACnet-based, so anything that can route BACnet to the controller can do this. Physical access to a mechanical room panel is an equally valid path.
What to do
Effectively unpatchable as a class - the vendor's guidance for this family is defensive positioning rather than a fix that adds authentication to the programming path, because the programming protocol was never designed with any. The only real control is to make the controllers unreachable: isolated VLAN carrying BACnet only, explicit allow-list from the Alerton supervisor (Compass/Envision) and nothing else, no internet path, port security on the switch ports feeding mechanical rooms, and physical locks on control panels. Where Honeywell offers a newer controller generation with authenticated programming, replacing the controllers is the actual fix and it is a capital project. In a leased site, you cannot touch these - require the landlord to attest that BACnet programming traffic is not routable from any tenant or corporate network.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.