Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
tuxedo touch vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2015-2847
Honeywell Tuxedo Touch prior to 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote malicious users to bypass intended access restrictions by removing USERACCT requests from the client-server data stream.
Honeywell Tuxedo Touch
1 Article
6.8
CVSSv2
CVE-2015-2848
Cross-site request forgery (CSRF) vulnerability in Honeywell Tuxedo Touch prior to 5.2.19.0_VA allows remote malicious users to hijack the authentication of arbitrary users for requests associated with home-automation commands, as demonstrated by a door-unlock command.
Honeywell Tuxedo Touch
1 Article
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4040
cross-site scripting
CVE-2023-25790
CVE-2024-2961
XML external entity
CVE-2024-26926
CVE-2024-32806
CVE-2024-32711
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started