Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2014-2717

HIGH · 7.6 CVSS Gepubliceerd:

Beschrijving NL

Honeywell FALCON XLWeb Linux-controllerapparaten 2.04.01 en eerder en FALCON XLWeb XLWebExe-controllerapparaten 2.02.11 en eerder stellen externe aanvallers in staat om authenticatie te omzeilen en administratieve toegang te verkrijgen door naar de pagina voor het wijzigen van wachtwoorden te gaan.

Origineel (Engels) tonen

Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.

Vendors

Honeywell

Affected products

Falcon Xlweb Linux Controller Falcon Xlweb Xlwebexe

References