Vulnerabilities > Honeywell > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-01-26 CVE-2020-27297 Out-of-bounds Write vulnerability in Honeywell OPC UA Tunneller
The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions prior to 6.3.0.8233).
network
low complexity
honeywell CWE-787
critical
9.8
2020-04-07 CVE-2020-6974 Path Traversal vulnerability in Honeywell Notifier Webserver 3.50
Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories.
network
low complexity
honeywell CWE-22
critical
9.8
2020-03-24 CVE-2020-6972 Authentication Bypass by Capture-replay vulnerability in Honeywell Notifier Webserver 3.50
In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.
network
low complexity
honeywell CWE-294
critical
9.1
2020-01-22 CVE-2020-6960 SQL Injection vulnerability in Honeywell products
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges.
network
low complexity
honeywell CWE-89
critical
9.8
2020-01-22 CVE-2020-6959 Deserialization of Untrusted Data vulnerability in Honeywell products
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data.
network
low complexity
honeywell CWE-502
critical
9.8
2019-10-31 CVE-2019-18226 Authentication Bypass by Capture-replay vulnerability in Honeywell products
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.
network
low complexity
honeywell CWE-294
critical
9.8
2019-04-08 CVE-2014-9186 Improper Input Validation vulnerability in Honeywell Experion Process Knowledge System R400/R410/R430
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code execution.
network
low complexity
honeywell CWE-20
critical
9.8
2019-04-08 CVE-2014-5435 Out-of-bounds Write vulnerability in Honeywell Experion Process Knowledge System R400/R410/R430
An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote code execution or denial of service.
network
low complexity
honeywell CWE-787
critical
9.8
2019-03-25 CVE-2014-9189 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Honeywell Experion Process Knowledge System R400/R410/R430
Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that could lead to possible remote code execution, dynamic memory corruption, or denial of service.
network
low complexity
honeywell CWE-119
critical
9.8
2019-03-25 CVE-2014-9187 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Honeywell Experion Process Knowledge System R400/R410/R430
Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could lead to possible remote code execution or denial of service.
network
low complexity
honeywell CWE-119
critical
9.8