VYPR

Notifier Web Server

by Honeywell

CVEs (2)

  • CVE-2020-6974CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.02

    Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem.

  • CVE-2020-6972CriMar 24, 2020
    risk 0.59cvss 9.1epss 0.01

    In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.