7.5

CVE-2019-18230

Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.

Data is provided by the National Vulnerability Database (NVD)
HoneywellH4d8pr1 Firmware Version < 1.000.hw01.3.20190820
   HoneywellH4d8pr1 Version-
HoneywellHfd5pr1 Firmware Version < 1.000.hw01.1.20190822
   HoneywellHfd5pr1 Version-
HoneywellHpw2p1 Firmware Version < 1.000.hw01.3.20190820
   HoneywellHpw2p1 Version-
HoneywellHdzp304di Firmware Version < 1.000.hw10.5.20190812
   HoneywellHdzp304di Version-
HoneywellHdzp252di Firmware Version < 1.000.hw02.3.20181109
   HoneywellHdzp252di Version-
HoneywellHdz302din-s1 Firmware Version < 1.000.0041.20180530
   HoneywellHdz302din-s1 Version-
HoneywellHdz302lik Firmware Version < 1.000.61.1.20180607
   HoneywellHdz302lik Version-
HoneywellHdz302liw Firmware Version < 1.000.61.1.20180607
   HoneywellHdz302liw Version-
HoneywellHfd6gr1 Firmware Version < 1.000.hw00.9.20180510
   HoneywellHfd6gr1 Version-
HoneywellHfd8gr1 Firmware Version < 1.000.hw00.9.20180510
   HoneywellHfd8gr1 Version-
HoneywellHm4l8gr1 Firmware Version < 1.000.hw02.8.20190813
   HoneywellHm4l8gr1 Version-
HoneywellHmbl8gr1 Firmware Version < 1.000.hw02.8.20190813
   HoneywellHmbl8gr1 Version-
HoneywellH2w2gr1 Firmware Version < 1.000.0000.18.20190409
   HoneywellH2w2gr1 Version-
HoneywellH3w2gr1 Firmware Version < 1.000.hw00.21.20190812
   HoneywellH3w2gr1 Version-
HoneywellH3w2gr1v Firmware Version < 1.000.0000.18.20190409
   HoneywellH3w2gr1v Version-
HoneywellH3w2gr2 Firmware Version < 1.000.hw00.21.20190812
   HoneywellH3w2gr2 Version-
HoneywellH3w4gr1 Firmware Version < 1.000.hw00.21.20190812
   HoneywellH3w4gr1 Version-
HoneywellH3w4gr1v Firmware Version < 1.000.0000.18.20190409
   HoneywellH3w4gr1v Version-
HoneywellH4d8gr1 Firmware Version < 2.420.hw00.9.20180510
   HoneywellH4d8gr1 Version-
HoneywellH4l2gr1 Firmware Version < 1.000.0000.18.20190423
   HoneywellH4l2gr1 Version-
HoneywellH4l2gr1v Firmware Version < 1.000.0000.18.20190423
   HoneywellH4l2gr1v Version-
HoneywellH4l6gr2 Firmware Version < 1.000.hw02.8.20190813
   HoneywellH4l6gr2 Version-
HoneywellH4lggr2 Firmware Version < 1.000.hw04.3.20190813
   HoneywellH4lggr2 Version-
HoneywellH4w2gr1 Firmware Version < 1.000.hw00.21.20190812
   HoneywellH4w2gr1 Version-
HoneywellH4w2gr1v Firmware Version < 1.000.0000.18.20190409
   HoneywellH4w2gr1v Version-
HoneywellH4w2gr2 Firmware Version < 1.000.hw00.21.20190812
   HoneywellH4w2gr2 Version-
HoneywellH4w4gr1 Firmware Version < 1.000.hw00.21.20190812
   HoneywellH4w4gr1 Version-
HoneywellH4w4gr1v Firmware Version < 1.000.0000.18.20190409
   HoneywellH4w4gr1v Version-
HoneywellHbd8gr1 Firmware Version < 2.420.hw00.9.20180510
   HoneywellHbd8gr1 Version-
HoneywellHbl2gr1 Firmware Version < 2.420.hw01.33.20190812
   HoneywellHbl2gr1 Version-
HoneywellHbl2gr1v Firmware Version < 1.000.0000.18.20190423
   HoneywellHbl2gr1v Version-
HoneywellHbl6gr2 Firmware Version < 1.000.hw04.3.20190813
   HoneywellHbl6gr2 Version-
HoneywellHbl6gr2 Firmware Version < 1.000.hw02.8.20190813
   HoneywellHbl6gr2 Version-
HoneywellHbw2gr1 Firmware Version < 1.000.hw00.21.20190812
   HoneywellHbw2gr1 Version-
HoneywellHbw2gr1v Firmware Version < 1.000.0000.18.20190409
   HoneywellHbw2gr1v Version-
HoneywellHbw2gr3 Firmware Version < 1.000.hw00.21.20190812
   HoneywellHbw2gr3 Version-
HoneywellHbw2gr3v Firmware Version < 1.000.0000.18.20190409
   HoneywellHbw2gr3v Version-
HoneywellHbw4gr1 Firmware Version < 1.000.hw00.21.20190812
   HoneywellHbw4gr1 Version-
HoneywellHbw4gr1v Firmware Version < 1.000.0000.18.20190409
   HoneywellHbw4gr1v Version-
HoneywellHcd8g Firmware Version < 2.420.hw00.9.20180510
   HoneywellHcd8g Version-
HoneywellHcl2g Firmware Version < 1.000.0000.18.20190423
   HoneywellHcl2g Version-
HoneywellHcl2gv Firmware Version < 1.000.0000.18.20190423
   HoneywellHcl2gv Version-
HoneywellHcw2g Firmware Version < 1.000.hw00.21.20190812
   HoneywellHcw2g Version-
HoneywellHcw2gv Firmware Version < 1.000.0000.18.20190409
   HoneywellHcw2gv Version-
HoneywellHcw4g Firmware Version < 1.000.hw00.21.20190812
   HoneywellHcw4g Version-
HoneywellHdz302d Firmware Version < 1.000.0041.20180530
   HoneywellHdz302d Version-
HoneywellHdz302de Firmware Version < 1.000.0041.20180530
   HoneywellHdz302de Version-
HoneywellHdz302din Firmware Version < 1.000.0041.20180530
   HoneywellHdz302din Version-
HoneywellHdz302din-c1 Firmware Version < 1.000.0041.20180530
   HoneywellHdz302din-c1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.26% 0.46
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.