Vulnerability index

Browse CVEs

98 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Alerton Bcm Web Firmware CRITICAL 9.8
CVE-2023-3243

** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salt…

Mitigation only
Fix from $2,300 2023-06-28
Onewireless Network Wireless Device Manager Firmware HIGH 7.5
CVE-2022-4240

Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless vers…

Mitigation only
Fix from $1,950 2023-05-30
Onewireless Network Wireless Device Manager Firmware MEDIUM 6.8
CVE-2022-46361

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system com…

Mitigation only
Fix from $1,600 2023-05-30
Onewireless Network Wireless Device Manager Firmware MEDIUM 6.5
CVE-2022-43485

Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This …

Mitigation only
Fix from $1,600 2023-05-30
C200 Firmware HIGH 7.5
CVE-2021-38399

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauth…

Mitigation only
Fix from $1,950 2022-10-28
C200 Firmware CRITICAL 10.0
CVE-2021-38397

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely ex…

Mitigation only
Fix from $2,300 2022-10-28
C200 Firmware CRITICAL 9.8
CVE-2021-38395

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allo…

Mitigation only
Fix from $2,300 2022-10-28
Softmaster HIGH 7.8
CVE-2022-2332

A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment.

Mitigation only
Fix from $1,950 2022-09-16
Softmaster HIGH 7.8
CVE-2022-2333

If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster…

Mitigation only
Fix from $1,950 2022-09-16
Trend Iq412 Firmware MEDIUM 6.5
CVE-2022-30312

The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Tre…

Mitigation only
Fix from $1,600 2022-09-07
Controledge Plc Firmware CRITICAL 9.8
CVE-2022-30318

Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials…

Mitigation only
Fix from $2,300 2022-08-31
Experion Lx Firmware CRITICAL 9.1
CVE-2022-30317

Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experi…

Mitigation only
Fix from $2,300 2022-08-31
Safety Manager Firmware CRITICAL 9.8
CVE-2022-30315

Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0053…

Mitigation only
Fix from $2,300 2022-07-28
Saia Pg5 Controls Suite HIGH 8.1
CVE-2022-30319

Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a Saia Burgess Controls (SBC) …

Mitigation only
Fix from $1,950 2022-07-28
Safety Manager Firmware MEDIUM 6.8
CVE-2022-30316

Honeywell Experion PKS Safety Manager 5.02 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0054, there is a Honeywell Expe…

No fix yet
Fix from $1,600 2022-07-28
Safety Manager Firmware HIGH 7.5
CVE-2022-30313

Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a …

Mitigation only
Fix from $1,950 2022-07-28
Alterton Visual Logic Firmware HIGH 8.8
CVE-2022-30243

Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be stored on the …

Fix: after 2022-05-04
Fix from $1,950 2022-07-15
Alerton Ascent Control Module Firmware HIGH 8.0
CVE-2022-30244

Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be…

Fix: after 2022-05-04
Fix from $1,950 2022-07-15
Alerton Ascent Control Module Firmware MEDIUM 6.8
CVE-2022-30242

Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated configuration changes from remote users. This enables configu…

Fix: after 2022-05-04
Fix from $1,600 2022-07-15
Alerton Compass MEDIUM 6.5
CVE-2022-30245

Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored…

Mitigation only
Fix from $1,600 2022-07-15
Matrikon Opc Server HIGH 8.8
CVE-2022-1261

Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to …

Mitigation only
Fix from $1,950 2022-05-26
Hdzp252di Firmware CRITICAL 9.8
CVE-2021-39363

Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.

Mitigation only
Fix from $2,300 2022-02-24
Hdzp252di Firmware HIGH 7.5
CVE-2021-39364

Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achi…

Mitigation only
Fix from $1,950 2022-02-24
Opc Ua Tunneller HIGH 7.5
CVE-2020-27295

The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA T…

Fix: 6.3.0.8233+
Fix from $1,950 2021-01-26
Opc Ua Tunneller CRITICAL 9.1
CVE-2020-27299

The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause t…

Fix: 6.3.0.8233+
Fix from $2,300 2021-01-26
Opc Ua Tunneller CRITICAL 9.8
CVE-2020-27297

The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remot…

Fix: 6.3.0.8233+
Fix from $2,300 2021-01-26
Opc Ua Tunneller HIGH 7.5
CVE-2020-27274

Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which …

Fix: 6.3.0.8233+
Fix from $1,950 2021-01-26
Controledge Plc Firmware HIGH 7.5
CVE-2020-10628

ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.

Mitigation only
Fix from $1,950 2020-06-26
Controledge Plc Firmware HIGH 7.5
CVE-2020-10624

ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.

Mitigation only
Fix from $1,950 2020-06-26
Notifier Webserver CRITICAL 9.8
CVE-2020-6974

Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted di…

Fix: after 3.50
Fix from $2,300 2020-04-07