CVE-2014-2717
Published Jul 24, 2014
Last updated 10 years ago
Overview
- Description
- Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.6
- Impact score
- 10
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Evaluator
- Comment
- <a href="http://cwe.mitre.org/data/definitions/552.html" target="_blank">CWE-552: CWE-552: Files or Directories Accessible to External Parties</a>
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:honeywell:falcon_xlweb_linux_controller:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCD8DDD2-BB5C-4EB4-9475-67F5B6341DBD", "versionEndIncluding": "2.04.01" }, { "criteria": "cpe:2.3:h:honeywell:falcon_xlweb_xlwebexe:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33EAB24D-D7D1-46B5-9740-3A33425AE027", "versionEndIncluding": "2.02.11" } ], "operator": "OR" } ] } ]