In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Honeywell
Subscribe
|
H2w2pc1m
Subscribe
H2w2pc1m Firmware
Subscribe
H2w2per3
Subscribe
H2w2per3 Firmware
Subscribe
H2w4per3
Subscribe
H2w4per3 Firmware
Subscribe
H4d3prv2
Subscribe
H4d3prv2 Firmware
Subscribe
H4d3prv3
Subscribe
H4d3prv3 Firmware
Subscribe
H4w2per2
Subscribe
H4w2per2 Firmware
Subscribe
H4w2per3
Subscribe
H4w2per3 Firmware
Subscribe
H4w8pr2
Subscribe
H4w8pr2 Firmware
Subscribe
Hbd3pr1
Subscribe
Hbd3pr1 Firmware
Subscribe
Hbd3pr2
Subscribe
Hbd3pr2 Firmware
Subscribe
Hbw2per1
Subscribe
Hbw2per1 Firmware
Subscribe
Hbw2per2
Subscribe
Hbw2per2 Firmware
Subscribe
Hbw8pr2
Subscribe
Hbw8pr2 Firmware
Subscribe
Hed3pr3
Subscribe
Hed3pr3 Firmware
Subscribe
Hen04103
Subscribe
Hen04103 Firmware
Subscribe
Hen04103l
Subscribe
Hen04103l Firmware
Subscribe
Hen04113
Subscribe
Hen04113 Firmware
Subscribe
Hen04123
Subscribe
Hen04123 Firmware
Subscribe
Hen08103
Subscribe
Hen08103 Firmware
Subscribe
Hen08103l
Subscribe
Hen08103l Firmware
Subscribe
Hen08104
Subscribe
Hen08104 Firmware
Subscribe
Hen081124
Subscribe
Hen081124 Firmware
Subscribe
Hen08113
Subscribe
Hen08113 Firmware
Subscribe
Hen08123
Subscribe
Hen08123 Firmware
Subscribe
Hen08143
Subscribe
Hen08143 Firmware
Subscribe
Hen08144
Subscribe
Hen08144 Firmware
Subscribe
Hen16103
Subscribe
Hen16103 Firmware
Subscribe
Hen16103l
Subscribe
Hen16103l Firmware
Subscribe
Hen16104
Subscribe
Hen16104 Firmware
Subscribe
Hen16123
Subscribe
Hen16123 Firmware
Subscribe
Hen16143
Subscribe
Hen16143 Firmware
Subscribe
Hen16144
Subscribe
Hen16144 Firmware
Subscribe
Hen16163
Subscribe
Hen16163 Firmware
Subscribe
Hen16184
Subscribe
Hen16184 Firmware
Subscribe
Hen16204
Subscribe
Hen16204 Firmware
Subscribe
Hen162244
Subscribe
Hen162244 Firmware
Subscribe
Hen16284
Subscribe
Hen16284 Firmware
Subscribe
Hen16304
Subscribe
Hen16304 Firmware
Subscribe
Hen16384
Subscribe
Hen16384 Firmware
Subscribe
Hen32103l
Subscribe
Hen32103l Firmware
Subscribe
Hen32104
Subscribe
Hen32104 Firmware
Subscribe
Hen321124
Subscribe
Hen321124 Firmware
Subscribe
Hen32204
Subscribe
Hen32204 Firmware
Subscribe
Hen322164
Subscribe
Hen322164 Firmware
Subscribe
Hen32284
Subscribe
Hen32284 Firmware
Subscribe
Hen32304
Subscribe
Hen32304 Firmware
Subscribe
Hen323164
Subscribe
Hen323164 Firmware
Subscribe
Hen32384
Subscribe
Hen32384 Firmware
Subscribe
Hen64204
Subscribe
Hen64204 Firmware
Subscribe
Hen64304
Subscribe
Hen64304 Firmware
Subscribe
Hen643164
Subscribe
Hen643164 Firmware
Subscribe
Hen643324
Subscribe
Hen643324 Firmware
Subscribe
Hen643484
Subscribe
Hen643484 Firmware
Subscribe
Hew2per2
Subscribe
Hew2per2 Firmware
Subscribe
Hew2per3
Subscribe
Hew2per3 Firmware
Subscribe
Hew4per2
Subscribe
Hew4per2 Firmware
Subscribe
Hew4per2b
Subscribe
Hew4per2b Firmware
Subscribe
Hew4per3b
Subscribe
Hew4per3b Firmware
Subscribe
Hpw2p1
Subscribe
Hpw2p1 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4978 | In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.us-cert.gov/ics/advisories/icsa-19-260-03 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-04T23:57:39.391Z
Reserved: 2019-07-11T00:00:00
Link: CVE-2019-13523
No data.
Status : Modified
Published: 2019-09-26T16:15:11.067
Modified: 2024-11-21T04:25:04.220
Link: CVE-2019-13523
No data.
OpenCVE Enrichment
No data.
EUVD