Skip to main content

Vendor/product archive

honeywell / tuxedo_touch CVEs

Beta · best-effort

2 CVEs tagged to honeywell / tuxedo_touch0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2015-2848

Published Jul 26, 2015

Cross-site request forgery (CSRF) vulnerability in Honeywell Tuxedo Touch before 5.2.19.0_VA allows remote attackers to hijack the authentication of arbitrary users for requests a…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2847

Published Jul 26, 2015

Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removi…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1