9.8

CVE-2019-18226

Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HoneywellH2w2pc1m Firmware Version-
   HoneywellH2w2pc1m Version-
HoneywellH2w2per3 Firmware Version-
   HoneywellH2w2per3 Version-
HoneywellH2w4per3 Firmware Version-
   HoneywellH2w4per3 Version-
HoneywellH4w2per2 Firmware Version-
   HoneywellH4w2per2 Version-
HoneywellH4w2per3 Firmware Version-
   HoneywellH4w2per3 Version-
HoneywellH4w4per2 Firmware Version-
   HoneywellH4w4per2 Version-
HoneywellH4w4per3 Firmware Version-
   HoneywellH4w4per3 Version-
HoneywellH4w8pr2 Firmware Version-
   HoneywellH4w8pr2 Version-
HoneywellHbd2per1 Firmware Version-
   HoneywellHbd2per1 Version-
HoneywellHbw2per1 Firmware Version-
   HoneywellHbw2per1 Version-
HoneywellHbw2per2 Firmware Version-
   HoneywellHbw2per2 Version-
HoneywellHbw4per1 Firmware Version-
   HoneywellHbw4per1 Version-
HoneywellHbw4per2 Firmware Version-
   HoneywellHbw4per2 Version-
HoneywellHbw4pgr1 Firmware Version-
   HoneywellHbw4pgr1 Version-
HoneywellHbw8pr2 Firmware Version-
   HoneywellHbw8pr2 Version-
HoneywellHed2per3 Firmware Version-
   HoneywellHed2per3 Version-
HoneywellHew2per2 Firmware Version-
   HoneywellHew2per2 Version-
HoneywellHew2per3 Firmware Version-
   HoneywellHew2per3 Version-
HoneywellHew4per2b Firmware Version-
   HoneywellHew4per2b Version-
HoneywellHew4per3 Firmware Version-
   HoneywellHew4per3 Version-
HoneywellHew4per3b Firmware Version-
   HoneywellHew4per3b Version-
HoneywellHew4per2b Firmware Version-
   HoneywellHew4per2b Version-
HoneywellHdzp252di Firmware Version-
   HoneywellHdzp252di Version-
HoneywellHdzp304di Firmware Version-
   HoneywellHdzp304di Version-
HoneywellHpw2p1 Firmware Version-
   HoneywellHpw2p1 Version-
HoneywellH2w2gr1 Firmware Version-
   HoneywellH2w2gr1 Version-
HoneywellH3w2gr1v Firmware Version-
   HoneywellH3w2gr1v Version-
HoneywellH3w4gr1v Firmware Version-
   HoneywellH3w4gr1v Version-
HoneywellH3w2gr1 Firmware Version-
   HoneywellH3w2gr1 Version-
HoneywellH3w2gr2 Firmware Version-
   HoneywellH3w2gr2 Version-
HoneywellH3w4gr1 Firmware Version-
   HoneywellH3w4gr1 Version-
HoneywellH4l2gr1v Firmware Version-
   HoneywellH4l2gr1v Version-
HoneywellH4w2gr1 Firmware Version-
   HoneywellH4w2gr1 Version-
HoneywellH4w2gr1v Firmware Version-
   HoneywellH4w2gr1v Version-
HoneywellH4w4gr1v Firmware Version-
   HoneywellH4w4gr1v Version-
HoneywellH4l2gr1 Firmware Version-
   HoneywellH4l2gr1 Version-
HoneywellH4w2gr2 Firmware Version-
   HoneywellH4w2gr2 Version-
HoneywellH4w4gr1 Firmware Version-
   HoneywellH4w4gr1 Version-
HoneywellH4l6gr2 Firmware Version-
   HoneywellH4l6gr2 Version-
HoneywellHm4l8gr1 Firmware Version-
   HoneywellHm4l8gr1 Version-
HoneywellH4d8gr1 Firmware Version-
   HoneywellH4d8gr1 Version-
HoneywellHbl2gr1v Firmware Version-
   HoneywellHbl2gr1v Version-
HoneywellHbw2gr1v Firmware Version-
   HoneywellHbw2gr1v Version-
HoneywellHbw2gr3v Firmware Version-
   HoneywellHbw2gr3v Version-
HoneywellHbw4gr1v Firmware Version-
   HoneywellHbw4gr1v Version-
HoneywellHbl6gr2 Firmware Version-
   HoneywellHbl6gr2 Version-
HoneywellHmbl8gr1 Firmware Version-
   HoneywellHmbl8gr1 Version-
HoneywellHbd8gr1 Firmware Version-
   HoneywellHbd8gr1 Version-
HoneywellHfd6gr1 Firmware Version-
   HoneywellHfd6gr1 Version-
HoneywellHfd8gr1 Firmware Version-
   HoneywellHfd8gr1 Version-
HoneywellHdz302liw Firmware Version-
   HoneywellHdz302liw Version-
HoneywellHdz302lik Firmware Version-
   HoneywellHdz302lik Version-
HoneywellHdz302de Firmware Version-
   HoneywellHdz302de Version-
HoneywellHdz302d Firmware Version-
   HoneywellHdz302d Version-
HoneywellHdz302din-c1 Firmware Version-
   HoneywellHdz302din-c1 Version-
HoneywellHdz302din-s1 Firmware Version-
   HoneywellHdz302din-s1 Version-
HoneywellHepz302w0 Firmware Version-
   HoneywellHepz302w0 Version-
HoneywellHcl2gv Firmware Version-
   HoneywellHcl2gv Version-
HoneywellHcl2g Firmware Version-
   HoneywellHcl2g Version-
HoneywellHcw2g Firmware Version-
   HoneywellHcw2g Version-
HoneywellHcw4g Firmware Version-
   HoneywellHcw4g Version-
HoneywellHcd8g Firmware Version-
   HoneywellHcd8g Version-
HoneywellHsw2g1 Firmware Version-
   HoneywellHsw2g1 Version-
HoneywellHswb2g1 Firmware Version-
   HoneywellHswb2g1 Version-
HoneywellHcw2gv Firmware Version-
   HoneywellHcw2gv Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.361
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-294 Authentication Bypass by Capture-replay

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).