Vulnerabilities > CVE-2014-2717 - Unspecified vulnerability in Honeywell products

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.

Vulnerable Configurations

Part Description Count
Hardware
Honeywell
2

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/131596/honeywell-traversal.txt
idPACKETSTORM:131596
last seen2016-12-05
published2015-04-23
reporterMartin Jartelius
sourcehttps://packetstormsecurity.com/files/131596/Honeywell-XLWEB-SCADA-Path-Traversal.html
titleHoneywell XLWEB SCADA Path Traversal