The convergence of operational technology and information technology has turned modern buildings into attractive targets for cyber adversaries.

Legacy building automation protocols such as BACnet and LonWorks were conceived in an era when network security was an afterthought, leaving many controllers exposed to unauthenticated access.

As smart buildings proliferate across campuses, hospitals, and commercial complexes, the attack surface expands dramatically, and threat actors have begun exploiting these weaknesses to gain footholds that can cascade into safety‑critical systems.

Recognizing this growing risk, cybersecurity agencies and vendors have issued a flurry of advisories highlighting severe vulnerabilities in widely deployed controllers.

In this landscape, defenders need lightweight, accessible tools that can quickly identify exposures without demanding deep expertise in penetration testing or expensive commercial licenses.

The release of BAS Guardian addresses exactly that gap, offering a free, open‑source scanner that translates the latest CISA ICS advisories into actionable network checks for facility and OT teams.

One of the most alarming findings driving the urgency behind BAS Guardian is CVE‑2026-3611, which carries a maximum CVSS score of 10.0 and affects Honeywell IQ4x series controllers.

This vulnerability stems from an improper authentication mechanism in the BACnet/IP service, allowing an unauthenticated remote attacker to execute arbitrary commands or manipulate critical points such as temperature setpoints, damper positions, or safety interlocks.

Because the flaw resides in a core communications stack that is often left listening on default UDP/TCP ports, a simple network sweep can reveal dozens of susceptible devices across a campus.

Exploitation does not require sophisticated malware; a crafted BACnet packet sent from the internet or an internal compromised host can reprogram logic controllers, potentially disrupting HVAC operation during extreme weather or enabling unauthorized access to secured areas.

The CVSS 10.0 rating reflects both the ease of exploitation and the severe impact on confidentiality, integrity, and availability of building functions.