In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.

Project Subscriptions

Vendors Products
Honeywell Subscribe
H2w2pc1m Subscribe
H2w2pc1m Firmware Subscribe
H2w2per3 Subscribe
H2w2per3 Firmware Subscribe
H2w4per3 Subscribe
H2w4per3 Firmware Subscribe
H4d3prv2 Subscribe
H4d3prv2 Firmware Subscribe
H4d3prv3 Subscribe
H4d3prv3 Firmware Subscribe
H4w2per2 Subscribe
H4w2per2 Firmware Subscribe
H4w2per3 Subscribe
H4w2per3 Firmware Subscribe
H4w8pr2 Subscribe
H4w8pr2 Firmware Subscribe
Hbd3pr1 Subscribe
Hbd3pr1 Firmware Subscribe
Hbd3pr2 Subscribe
Hbd3pr2 Firmware Subscribe
Hbw2per1 Subscribe
Hbw2per1 Firmware Subscribe
Hbw2per2 Subscribe
Hbw2per2 Firmware Subscribe
Hbw8pr2 Subscribe
Hbw8pr2 Firmware Subscribe
Hed3pr3 Subscribe
Hed3pr3 Firmware Subscribe
Hen04103 Subscribe
Hen04103 Firmware Subscribe
Hen04103l Subscribe
Hen04103l Firmware Subscribe
Hen04113 Subscribe
Hen04113 Firmware Subscribe
Hen04123 Subscribe
Hen04123 Firmware Subscribe
Hen08103 Subscribe
Hen08103 Firmware Subscribe
Hen08103l Subscribe
Hen08103l Firmware Subscribe
Hen08104 Subscribe
Hen08104 Firmware Subscribe
Hen081124 Subscribe
Hen081124 Firmware Subscribe
Hen08113 Subscribe
Hen08113 Firmware Subscribe
Hen08123 Subscribe
Hen08123 Firmware Subscribe
Hen08143 Subscribe
Hen08143 Firmware Subscribe
Hen08144 Subscribe
Hen08144 Firmware Subscribe
Hen16103 Subscribe
Hen16103 Firmware Subscribe
Hen16103l Subscribe
Hen16103l Firmware Subscribe
Hen16104 Subscribe
Hen16104 Firmware Subscribe
Hen16123 Subscribe
Hen16123 Firmware Subscribe
Hen16143 Subscribe
Hen16143 Firmware Subscribe
Hen16144 Subscribe
Hen16144 Firmware Subscribe
Hen16163 Subscribe
Hen16163 Firmware Subscribe
Hen16184 Subscribe
Hen16184 Firmware Subscribe
Hen16204 Subscribe
Hen16204 Firmware Subscribe
Hen162244 Subscribe
Hen162244 Firmware Subscribe
Hen16284 Subscribe
Hen16284 Firmware Subscribe
Hen16304 Subscribe
Hen16304 Firmware Subscribe
Hen16384 Subscribe
Hen16384 Firmware Subscribe
Hen32103l Subscribe
Hen32103l Firmware Subscribe
Hen32104 Subscribe
Hen32104 Firmware Subscribe
Hen321124 Subscribe
Hen321124 Firmware Subscribe
Hen32204 Subscribe
Hen32204 Firmware Subscribe
Hen322164 Subscribe
Hen322164 Firmware Subscribe
Hen32284 Subscribe
Hen32284 Firmware Subscribe
Hen32304 Subscribe
Hen32304 Firmware Subscribe
Hen323164 Subscribe
Hen323164 Firmware Subscribe
Hen32384 Subscribe
Hen32384 Firmware Subscribe
Hen64204 Subscribe
Hen64204 Firmware Subscribe
Hen64304 Subscribe
Hen64304 Firmware Subscribe
Hen643164 Subscribe
Hen643164 Firmware Subscribe
Hen643324 Subscribe
Hen643324 Firmware Subscribe
Hen643484 Subscribe
Hen643484 Firmware Subscribe
Hew2per2 Subscribe
Hew2per2 Firmware Subscribe
Hew2per3 Subscribe
Hew2per3 Firmware Subscribe
Hew4per2 Subscribe
Hew4per2 Firmware Subscribe
Hew4per2b Subscribe
Hew4per2b Firmware Subscribe
Hew4per3b Subscribe
Hew4per3b Firmware Subscribe
Hpw2p1 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-4978 In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-04T23:57:39.391Z

Reserved: 2019-07-11T00:00:00

Link: CVE-2019-13523

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-26T16:15:11.067

Modified: 2024-11-21T04:25:04.220

Link: CVE-2019-13523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses