Show filters
113 Total Results
Displaying 61-70 of 113
Sort by:
Attacker Value
Unknown

CVE-2022-1261

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to the OPC server to use the functions of the IPersisFile to execute operating system processes with system-level privileges.
Attacker Value
Unknown

CVE-2021-39364

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
Attacker Value
Unknown

CVE-2021-39363

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.
Attacker Value
Unknown

CVE-2021-38399

Disclosure Date: October 05, 2021 (last updated December 22, 2024)
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.
Attacker Value
Unknown

CVE-2021-38397

Disclosure Date: October 05, 2021 (last updated December 22, 2024)
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
Attacker Value
Unknown

CVE-2021-38395

Disclosure Date: October 05, 2021 (last updated December 22, 2024)
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
Attacker Value
Unknown

CVE-2020-27295

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Attacker Value
Unknown

CVE-2020-27297

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Attacker Value
Unknown

CVE-2020-27274

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Attacker Value
Unknown

CVE-2020-27299

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause the device to crash on the OPC UA Tunneller (versions prior to 6.3.0.8233).