5.3

CVE-2019-13523

In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.

Data is provided by the National Vulnerability Database (NVD)
HoneywellHbd3pr2 Firmware Version-
   HoneywellHbd3pr2 Version-
HoneywellH4d3prv3 Firmware Version-
   HoneywellH4d3prv3 Version-
HoneywellHed3pr3 Firmware Version-
   HoneywellHed3pr3 Version-
HoneywellH4d3prv2 Firmware Version-
   HoneywellH4d3prv2 Version-
HoneywellHbd3pr1 Firmware Version-
   HoneywellHbd3pr1 Version-
HoneywellH4w8pr2 Firmware Version-
   HoneywellH4w8pr2 Version-
HoneywellHbw8pr2 Firmware Version-
   HoneywellHbw8pr2 Version-
HoneywellH2w2pc1m Firmware Version-
   HoneywellH2w2pc1m Version-
HoneywellH2w4per3 Firmware Version-
   HoneywellH2w4per3 Version-
HoneywellH2w2per3 Firmware Version-
   HoneywellH2w2per3 Version-
HoneywellHew2per3 Firmware Version-
   HoneywellHew2per3 Version-
HoneywellHew4per3b Firmware Version-
   HoneywellHew4per3b Version-
HoneywellHbw2per1 Firmware Version-
   HoneywellHbw2per1 Version-
HoneywellHew4per2 Firmware Version-
   HoneywellHew4per2 Version-
HoneywellHew4per2b Firmware Version-
   HoneywellHew4per2b Version-
HoneywellHew2per2 Firmware Version-
   HoneywellHew2per2 Version-
HoneywellH4w2per2 Firmware Version-
   HoneywellH4w2per2 Version-
HoneywellHbw2per2 Firmware Version-
   HoneywellHbw2per2 Version-
HoneywellH4w2per3 Firmware Version-
   HoneywellH4w2per3 Version-
HoneywellHpw2p1 Firmware Version-
   HoneywellHpw2p1 Version-
HoneywellHen08104 Firmware Version-
   HoneywellHen08104 Version-
HoneywellHen08144 Firmware Version-
   HoneywellHen08144 Version-
HoneywellHen081124 Firmware Version-
   HoneywellHen081124 Version-
HoneywellHen16104 Firmware Version-
   HoneywellHen16104 Version-
HoneywellHen16144 Firmware Version-
   HoneywellHen16144 Version-
HoneywellHen16184 Firmware Version-
   HoneywellHen16184 Version-
HoneywellHen16204 Firmware Version-
   HoneywellHen16204 Version-
HoneywellHen162244 Firmware Version-
   HoneywellHen162244 Version-
HoneywellHen16284 Firmware Version-
   HoneywellHen16284 Version-
HoneywellHen16304 Firmware Version-
   HoneywellHen16304 Version-
HoneywellHen16384 Firmware Version-
   HoneywellHen16384 Version-
HoneywellHen32104 Firmware Version-
   HoneywellHen32104 Version-
HoneywellHen321124 Firmware Version-
   HoneywellHen321124 Version-
HoneywellHen32204 Firmware Version-
   HoneywellHen32204 Version-
HoneywellHen32284 Firmware Version-
   HoneywellHen32284 Version-
HoneywellHen322164 Firmware Version-
   HoneywellHen322164 Version-
HoneywellHen32304 Firmware Version-
   HoneywellHen32304 Version-
HoneywellHen32384 Firmware Version-
   HoneywellHen32384 Version-
HoneywellHen323164 Firmware Version-
   HoneywellHen323164 Version-
HoneywellHen64204 Firmware Version-
   HoneywellHen64204 Version-
HoneywellHen64304 Firmware Version-
   HoneywellHen64304 Version-
HoneywellHen643164 Firmware Version-
   HoneywellHen643164 Version-
HoneywellHen643324 Firmware Version-
   HoneywellHen643324 Version-
HoneywellHen643484 Firmware Version-
   HoneywellHen643484 Version-
HoneywellHen04103 Firmware Version-
   HoneywellHen04103 Version-
HoneywellHen04113 Firmware Version-
   HoneywellHen04113 Version-
HoneywellHen04123 Firmware Version-
   HoneywellHen04123 Version-
HoneywellHen08103 Firmware Version-
   HoneywellHen08103 Version-
HoneywellHen08113 Firmware Version-
   HoneywellHen08113 Version-
HoneywellHen08123 Firmware Version-
   HoneywellHen08123 Version-
HoneywellHen08143 Firmware Version-
   HoneywellHen08143 Version-
HoneywellHen16103 Firmware Version-
   HoneywellHen16103 Version-
HoneywellHen16123 Firmware Version-
   HoneywellHen16123 Version-
HoneywellHen16143 Firmware Version-
   HoneywellHen16143 Version-
HoneywellHen16163 Firmware Version-
   HoneywellHen16163 Version-
HoneywellHen04103l Firmware Version-
   HoneywellHen04103l Version-
HoneywellHen08103l Firmware Version-
   HoneywellHen08103l Version-
HoneywellHen16103l Firmware Version-
   HoneywellHen16103l Version-
HoneywellHen32103l Firmware Version-
   HoneywellHen32103l Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.27% 0.501
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.