Honeywell
honeywell
103 CVEs • 387 products
Products (387)
Click to collapseToggle
Products (387)
Click to collapse
CVEs (103)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Honeywell 14Ck75 Cn51Cn75+11 moreNov 21, 2024 Sep 24, 2018 N/A· v4 5.8 MEDIUM· v3 6.8 MEDIUM· v2 On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN75e running Android OS 6.0, CT50 running A...Show more |
1Honeywell 1Matrikonopc Explorer Jun 17, 2026 May 17, 2018 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 Honeywell MatrikonOPC OPC Controller before 5.1.0.0 allows local users to transfer arbitrary files from a host computer and consequently obtain sensitive information via vectors related to MSXML libraries. |
1Honeywell 7Enterprise Dvr Firmware Fusion Iv Rev C FirmwareMaxpro Nvr Hybrid Se Firmware+4 moreMay 13, 2026 Sep 11, 2017 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request t...Show more |
1Honeywell 7Intermec Pc23 Firmware Intermec Pc42 FirmwareIntermec Pc43 Firmware+4 moreMay 13, 2026 Mar 29, 2017 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users...Show more |
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal attack by accessing...Show more |
1Honeywell 1Xl Web Ii Controller May 13, 2026 Feb 13, 2017 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the parameters by accessing...Show more |
1Honeywell 1Xl Web Ii Controller May 13, 2026 Feb 13, 2017 N/A· v4 6.0 MEDIUM· v3 6.5 MEDIUM· v2 An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing s...Show more |
1Honeywell 1Xl Web Ii Controller May 13, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text. |
1Honeywell 1Xl Web Ii Controller May 13, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user is able to disclose a password by accessing a specific URL, because of P...Show more |
1Honeywell 1Experion Process Knowledge System May 13, 2026 Feb 13, 2017 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS, Release 3xx and prior, Experion PKS, Release 400, Experion PKS, Release 410, Experion PKS, Release 430, and Experion PK...Show more |
1Honeywell 1Uniformance Process History Database May 6, 2026 Apr 21, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors. |
1Honeywell 2Midas Black Firmware Midas FirmwareMay 6, 2026 Dec 21, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote attackers to discover cleartext passwords by sniffing the network. |
1Honeywell 2Midas Black Firmware Midas FirmwareMay 6, 2026 Dec 21, 2015 N/A· v4 8.6 HIGH· v3 6.4 MEDIUM· v2 Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuratio...Show more |
Cross-site request forgery (CSRF) vulnerability in Honeywell Tuxedo Touch before 5.2.19.0_VA allows remote attackers to hijack the authentication of arbitrary users for requests associated with home-automation commands,...Show more |
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-serv...Show more |
1Honeywell 8Excel Web Xl 1000c1000 600 I/o Excel Web Xl 1000c1000 600 I/o UuklExcel Web Xl 1000c100 104 I/o+5 moreMay 6, 2026 Mar 31, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300...Show more |
Multiple stack-based buffer overflows in (1) HWOPOSScale.ocx and (2) HWOPOSSCANNER.ocx in Honeywell OPOS Suite before 1.13.4.15 allow remote attackers to execute arbitrary code via a crafted file that is improperly handl...Show more |
1Honeywell 2Falcon Xlweb Linux Controller Falcon Xlweb XlwebexeMay 6, 2026 Jul 24, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject...Show more |
1Honeywell 2Falcon Xlweb Linux Controller Falcon Xlweb XlwebexeMay 6, 2026 Jul 24, 2014 N/A· v4 N/A· v3 7.6 HIGH· v2 Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by vis...Show more |
1Honeywell 3Comfortpoint Open Manager Station Enterprise Buildings IntegratorSymmetreApr 29, 2026 Feb 24, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HM...Show more |