The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Honeywell
Subscribe
|
Hnmswvms
Subscribe
Hnmswvms Firmware
Subscribe
Hnmswvmslt
Subscribe
Hnmswvmslt Firmware
Subscribe
Maxpro Nvr Pe
Subscribe
Maxpro Nvr Pe Firmware
Subscribe
Maxpro Nvr Se
Subscribe
Maxpro Nvr Se Firmware
Subscribe
Maxpro Nvr Xe
Subscribe
Maxpro Nvr Xe Firmware
Subscribe
Mpnvrswxx
Subscribe
Mpnvrswxx Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28100 | The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.us-cert.gov/ics/advisories/icsa-20-021-01 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-04T09:18:02.477Z
Reserved: 2020-01-14T00:00:00
Link: CVE-2020-6960
No data.
Status : Modified
Published: 2020-01-22T15:15:11.617
Modified: 2024-11-21T05:36:23.483
Link: CVE-2020-6960
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD