Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
honeywell xl web ii controller xlwebexe-1-02-08 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2017-5140
An issue exists in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text.
Honeywell Xl Web Ii Controller Xlwebexe-1-02-08
Honeywell Xl Web Ii Controller Xlwebexe-2-01-00
8.6
CVSSv3
CVE-2017-5143
An issue exists in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal attack by accessing a specific URL.
Honeywell Xl Web Ii Controller Xlwebexe-1-02-08
Honeywell Xl Web Ii Controller Xlwebexe-2-01-00
9.8
CVSSv3
CVE-2017-5139
An issue exists in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user is able to disclose a password by accessing a specific URL, because of Plaintext Storage of a Password.
Honeywell Xl Web Ii Controller Xlwebexe-2-01-00
Honeywell Xl Web Ii Controller Xlwebexe-1-02-08
9.1
CVSSv3
CVE-2017-5142
An issue exists in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the parameters by accessing a specific URL because of Improper Privilege Management.
Honeywell Xl Web Ii Controller Xlwebexe-1-02-08
Honeywell Xl Web Ii Controller Xlwebexe-2-01-00
6
CVSSv3
CVE-2017-5141
An issue exists in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticate...
Honeywell Xl Web Ii Controller Xlwebexe-1-02-08
Honeywell Xl Web Ii Controller Xlwebexe-2-01-00
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started