Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-14-175-01 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-07-24T14:00:00
Updated: 2024-08-06T10:21:36.077Z
Reserved: 2014-04-01T00:00:00
Link: CVE-2014-2717
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-07-24T14:55:07.363
Modified: 2024-11-21T02:06:49.553
Link: CVE-2014-2717
Redhat
No data.