Vulnerability index

Browse CVEs

55 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51605

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite HIGH 8.8
CVE-2023-51599

Honeywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2024-05-03
Saia Pg5 Controls Suite HIGH 8.8
CVE-2023-51603

Honeywell Saia PG5 Controls Suite CAB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacker…

Mitigation only
Fix from $1,950 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51600

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51601

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51602

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51604

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Controledge Unit Operations Controller Firmware MEDIUM 5.3
CVE-2023-5390

An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlE…

Mitigation only
Fix from $1,600 2024-01-31
Controledge Unit Operations Controller Firmware HIGH 7.5
CVE-2023-5389

An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and Con…

Mitigation only
Fix from $1,950 2024-01-30
Prowatch HIGH 7.8
CVE-2023-6179

Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker cou…

Mitigation only
Fix from $1,950 2023-11-17
Pm43 Firmware CRITICAL 9.8
CVE-2023-3710EPSS 33%

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 …

Mitigation only
Fix from $2,300 2023-09-12
Pm43 Firmware HIGH 8.8
CVE-2023-3711

Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction…

Mitigation only
Fix from $1,950 2023-09-12
Pm43 Firmware HIGH 7.8
CVE-2023-3712

Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escala…

Mitigation only
Fix from $1,950 2023-09-12
Alerton Bcm Web Firmware CRITICAL 9.8
CVE-2023-3243

** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salt…

Mitigation only
Fix from $2,300 2023-06-28
Onewireless Network Wireless Device Manager Firmware HIGH 7.5
CVE-2022-4240

Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless vers…

Mitigation only
Fix from $1,950 2023-05-30
Onewireless Network Wireless Device Manager Firmware MEDIUM 6.8
CVE-2022-46361

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system com…

Mitigation only
Fix from $1,600 2023-05-30
Onewireless Network Wireless Device Manager Firmware MEDIUM 6.5
CVE-2022-43485

Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This …

Mitigation only
Fix from $1,600 2023-05-30
C200 Firmware HIGH 7.5
CVE-2021-38399

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauth…

Mitigation only
Fix from $1,950 2022-10-28
C200 Firmware CRITICAL 10.0
CVE-2021-38397

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely ex…

Mitigation only
Fix from $2,300 2022-10-28
C200 Firmware CRITICAL 9.8
CVE-2021-38395

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allo…

Mitigation only
Fix from $2,300 2022-10-28
Softmaster HIGH 7.8
CVE-2022-2332

A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment.

Mitigation only
Fix from $1,950 2022-09-16
Softmaster HIGH 7.8
CVE-2022-2333

If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster…

Mitigation only
Fix from $1,950 2022-09-16
Trend Iq412 Firmware MEDIUM 6.5
CVE-2022-30312

The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Tre…

Mitigation only
Fix from $1,600 2022-09-07
Controledge Plc Firmware CRITICAL 9.8
CVE-2022-30318

Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials…

Mitigation only
Fix from $2,300 2022-08-31
Experion Lx Firmware CRITICAL 9.1
CVE-2022-30317

Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experi…

Mitigation only
Fix from $2,300 2022-08-31
Safety Manager Firmware CRITICAL 9.8
CVE-2022-30315

Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0053…

Mitigation only
Fix from $2,300 2022-07-28
Saia Pg5 Controls Suite HIGH 8.1
CVE-2022-30319

Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a Saia Burgess Controls (SBC) …

Mitigation only
Fix from $1,950 2022-07-28
Safety Manager Firmware MEDIUM 6.8
CVE-2022-30316

Honeywell Experion PKS Safety Manager 5.02 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0054, there is a Honeywell Expe…

No fix yet
Fix from $1,600 2022-07-28
Safety Manager Firmware HIGH 7.5
CVE-2022-30313

Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a …

Mitigation only
Fix from $1,950 2022-07-28
Alerton Compass MEDIUM 6.5
CVE-2022-30245

Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored…

Mitigation only
Fix from $1,600 2022-07-15