Vulnerabilities > CVE-2014-2717 - Authentication Bypass vulnerability in Honeywell products

047910
CVSS 7.6 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
high complexity
honeywell

Summary

Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page. <a href="http://cwe.mitre.org/data/definitions/552.html" target="_blank">CWE-552: CWE-552: Files or Directories Accessible to External Parties</a>

Vulnerable Configurations

Part Description Count
Hardware
Honeywell
2

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/131596/honeywell-traversal.txt
idPACKETSTORM:131596
last seen2016-12-05
published2015-04-23
reporterMartin Jartelius
sourcehttps://packetstormsecurity.com/files/131596/Honeywell-XLWEB-SCADA-Path-Traversal.html
titleHoneywell XLWEB SCADA Path Traversal