Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-2745 | Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://ics-cert.us-cert.gov/advisories/ICSA-14-175-01 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:21:36.077Z
Reserved: 2014-04-01T00:00:00
Link: CVE-2014-2717
No data.
Status : Deferred
Published: 2014-07-24T14:55:07.363
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-2717
No data.
OpenCVE Enrichment
No data.
EUVD