honeywell security advisories
14 threat alerts tracking vulnerabilities and security advisories that affect honeywell products.
Vulnios monitors honeywell CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent honeywell security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2020-27297 — honeywell — opc_ua_tunneller
The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions
criticalCVE-2020-27297Critical Vulnerability: CVE-2020-27299 — honeywell — opc_ua_tunneller
The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause the device to crash on the OPC UA Tunneller (version
criticalCVE-2020-27299Critical Vulnerability: CVE-2020-6974 — honeywell — notifier_webserver
Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update
criticalCVE-2020-6974Critical Vulnerability: CVE-2020-6972 — honeywell — notifier_webserver
In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.
criticalCVE-2020-6972Critical Vulnerability: CVE-2020-6960 — honeywell — maxpro_nvr_xe_firmware, maxpro_nvr_xe
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to
criticalCVE-2020-6960Critical Vulnerability: CVE-2020-6959 — honeywell — maxpro_nvr_xe_firmware, maxpro_nvr_xe
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to
criticalCVE-2020-6959Critical Vulnerability: CVE-2019-18226 — honeywell — h2w2pc1m_firmware, h2w2pc1m
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a
criticalCVE-2019-18226Critical Vulnerability: CVE-2014-9186 — honeywell — experion_process_knowledge_system
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file
criticalCVE-2014-9186Critical Vulnerability: CVE-2014-9189 — honeywell — experion_process_knowledge_system
Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that coul
criticalCVE-2014-9189Critical Vulnerability: CVE-2014-9187 — honeywell — experion_process_knowledge_system
Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could le
criticalCVE-2014-9187Critical Vulnerability: CVE-2017-5142 — honeywell — xl_web_ii_controller
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the par
criticalCVE-2017-5142Critical Vulnerability: CVE-2017-5139 — honeywell — xl_web_ii_controller
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user is able to disclose a password by accessing a specif
criticalCVE-2017-5139Critical Vulnerability: CVE-2017-5140 — honeywell — xl_web_ii_controller
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text.
criticalCVE-2017-5140Critical Vulnerability: CVE-2014-5435 — honeywell — experion_process_knowledge_system
An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote
criticalCVE-2014-5435
Track honeywell exposure across your environment
Vulnios automatically cross-references your asset inventory against new honeywell CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan