VYPR

Falcon Xlweb Linux Controller

Sign in to watch

by Honeywell

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2014-31100.030.02Jul 24, 2014Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input.
CVE-2014-27170.000.00Jul 24, 2014Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.