# Honeywell BEDQ API Access Control Flaw Exposed an Internal Engineering System

DevFeed: [Honeywell BEDQ API Access Control Flaw Exposed an Internal Engineering System](<https://devfeed.tech/articles/how-1-exposed-honeywell-api-gave-me-control-over-an-internal-engineering-system-32611.md>)

Original publisher: [Read original article](<https://eaton-works.com/2024/08/19/honeywell-bedq-hack/>)

Author: Eaton

Published: 2024-08-19T04:00:00Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [angular](<https://devfeed.tech/tags/angular.md>), [api](<https://devfeed.tech/tags/api.md>), [api-security](<https://devfeed.tech/tags/api-security.md>), [security](<https://devfeed.tech/tags/security.md>), [web-apps](<https://devfeed.tech/tags/web-apps.md>)

## AI overview

The article describes how an insecure API endpoint in Honeywell's BEDQ system exposed an internal engineering application. It examines weaknesses in access control between internal users and externally registered Honeywell IDs, and emphasizes the need for stronger API security.

## Source excerpt

(ASPEN) APIs are crucial for web apps but pose security risks. I uncovered a critical flaw in Honeywell's BEDQ system, highlighting the need for strong API security.