Show filters
113 Total Results
Displaying 71-80 of 113
Sort by:
Attacker Value
Unknown
CVE-2020-10628
Disclosure Date: June 26, 2020 (last updated February 21, 2025)
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.
0
Attacker Value
Unknown
CVE-2020-10624
Disclosure Date: June 26, 2020 (last updated February 21, 2025)
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
0
Attacker Value
Unknown
CVE-2020-6974
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem.
0
Attacker Value
Unknown
CVE-2020-6978
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.
0
Attacker Value
Unknown
CVE-2020-6982
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.
0
Attacker Value
Unknown
CVE-2020-7005
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.
0
Attacker Value
Unknown
CVE-2020-6972
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.
0
Attacker Value
Unknown
CVE-2020-6968
Disclosure Date: February 20, 2020 (last updated February 21, 2025)
Honeywell INNCOM INNControl 3 allows workstation users to escalate application user privileges through the modification of local configuration files.
0
Attacker Value
Unknown
CVE-2020-6960
Disclosure Date: January 22, 2020 (last updated February 21, 2025)
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges.
0
Attacker Value
Unknown
CVE-2020-6959
Disclosure Date: January 22, 2020 (last updated February 21, 2025)
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution.
0