The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.
Honeywell recommends users contact Honeywell at https://www.honeywell.com/us/en/contact/support for patch information.