Unknown
CVE-2019-13523
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2019-13523
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- h2w2pc1m firmware -,
- h2w2per3 firmware -,
- h2w4per3 firmware -,
- h4d3prv2 firmware -,
- h4d3prv3 firmware -,
- h4w2per2 firmware -,
- h4w2per3 firmware -,
- h4w8pr2 firmware -,
- hbd3pr1 firmware -,
- hbd3pr2 firmware -,
- hbw2per1 firmware -,
- hbw2per2 firmware -,
- hbw8pr2 firmware -,
- hed3pr3 firmware -,
- hen04103 firmware -,
- hen04103l firmware -,
- hen04113 firmware -,
- hen04123 firmware -,
- hen08103 firmware -,
- hen08103l firmware -,
- hen08104 firmware -,
- hen081124 firmware -,
- hen08113 firmware -,
- hen08123 firmware -,
- hen08143 firmware -,
- hen08144 firmware -,
- hen16103 firmware -,
- hen16103l firmware -,
- hen16104 firmware -,
- hen16123 firmware -,
- hen16143 firmware -,
- hen16144 firmware -,
- hen16163 firmware -,
- hen16184 firmware -,
- hen16204 firmware -,
- hen162244 firmware -,
- hen16284 firmware -,
- hen16304 firmware -,
- hen16384 firmware -,
- hen32103l firmware -,
- hen32104 firmware -,
- hen321124 firmware -,
- hen32204 firmware -,
- hen322164 firmware -,
- hen32284 firmware -,
- hen32304 firmware -,
- hen323164 firmware -,
- hen32384 firmware -,
- hen64204 firmware -,
- hen64304 firmware -,
- hen643164 firmware -,
- hen643324 firmware -,
- hen643484 firmware -,
- hew2per2 firmware -,
- hew2per3 firmware -,
- hew4per2 firmware -,
- hew4per2b firmware -,
- hew4per3b firmware -,
- hpw2p1 firmware -
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: