7.6
CVSSv2

CVE-2014-2717

Published: 24/07/2014 Updated: 25/07/2014
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Honeywell FALCON XLWeb Linux controller devices 2.04.01 and previous versions and FALCON XLWeb XLWebExe controller devices 2.02.11 and previous versions allow remote malicious users to bypass authentication and obtain administrative access by visiting the change-password page.

Vulnerable Product Search on Vulmon Subscribe to Product

honeywell falcon xlweb linux controller

honeywell falcon xlweb xlwebexe

Exploits

Honeywell XLWEB SCADA controller suffers from a remote path traversal vulnerability that allows for remote code execution ...