Improper Privilege Management in Honeywell XL Web II Controller
CVE-2017-5142

9.1CRITICAL

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
13 February 2017

What is CVE-2017-5142?

A vulnerability has been identified in the Honeywell XL Web II controller that allows a user with low privileges to access and modify system parameters via a specific URL. This issue arises from improper privilege management practices, leaving the affected systems open to unauthorized changes.

Affected Version(s)

Honeywell XL Web II Controller Honeywell XL Web II Controller

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.