Skip to main content

Vendor archive

honeywell CVEs

Beta · best-effort

103 CVEs tagged to vendor honeywell35 Critical, 36 High, 31 Medium, 1 Low, 0 Unrated.

CVE-2022-1261

Published May 26, 2022

Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to the OPC server to use the func…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27295

Published Jan 26, 2021

The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27299

Published Jan 26, 2021

The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause the device to crash on the OPC…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27297

Published Jan 26, 2021

The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27274

Published Jan 26, 2021

Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-servic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6974

Published Apr 7, 2020

Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has relea…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6982

Published Mar 24, 2020

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6978

Published Mar 24, 2020

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7005

Published Mar 24, 2020

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6972

Published Mar 24, 2020

In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6960

Published Jan 22, 2020

The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MA…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2020-6959

Published Jan 22, 2020

The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MA…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Showing 51-75 of 103 CVEsPage 3 of 5