← Back

Win Pak

win-pak

Vendor: Honeywell • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Honeywell
1Win Pak
Jun 17, 2026
Mar 24, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.
1Honeywell
1Win Pak
Jun 17, 2026
Mar 24, 2020
N/A· v4
7.2 HIGH· v3
6.4 MEDIUM· v2
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.
1Honeywell
1Win Pak
Jun 17, 2026
Mar 24, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.