VYPR
Vendor

Honeywell

Products
266
CVEs
132
Across products
159
Status
Private

Products

266
View all 266 products →

Recent CVEs

132
View all 132 CVEs →
  • CVE-2023-3710CriSep 12, 2023
    risk 0.70cvss 9.9epss 0.33

    Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5…

  • CVE-2026-3611CriMar 12, 2026
    risk 0.65cvss 10.0epss 0.06

    The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context,…

  • CVE-2025-2605CriMay 2, 2025
    risk 0.65cvss 9.9epss 0.13

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends…

  • CVE-2021-38397CriOct 28, 2022
    risk 0.65cvss 10.0epss 0.01

    Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.

  • CVE-2024-2421CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands with elevated permissions.

  • CVE-2024-2420CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.

  • CVE-2023-25770CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-25178CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-25078CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-24480CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Controller DoS due to stack overflow when decoding a message from the server.  See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-23585CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2022-30318CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.01

    Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potential impact is: Remote code execution, manipulate…

  • CVE-2022-30315CriJul 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0053, there is a Honeywell Experion PKS Safety Manager insufficient logic security controls issue. The affected components are…

  • CVE-2021-39363CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.

  • CVE-2020-27297CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.02

    The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions prior to 6.3.0.8233).

  • CVE-2020-6974CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.02

    Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem.

  • CVE-2020-6960CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.01

    The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6…

  • CVE-2020-6959CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.02

    The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6…

  • CVE-2019-18226CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.01

    Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.

  • CVE-2014-9186CriApr 8, 2019
    risk 0.64cvss 9.8epss 0.04

    A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code…