Clear Text Password Vulnerability in Honeywell XL Web II Controller
CVE-2017-5140

9.8CRITICAL

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
13 February 2017

What is CVE-2017-5140?

A security flaw has been identified within the Honeywell XL Web II Controller, specifically affecting the XL1000C500 and XLWeb 500 models. This vulnerability involves the storage of passwords in clear text, posing a significant risk of unauthorized access to sensitive systems and data. Implementing strong password management practices and regularly updating firmware can help mitigate potential security threats.

Affected Version(s)

Honeywell XL Web II Controller Honeywell XL Web II Controller

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.