CVE-2014-2717: High severity honeywell falcon xlweb vulnerability
Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2717?
CVE-2014-2717 is classified as a critical vulnerability due to its potential for remote attacker exploitation.
How do I fix CVE-2014-2717?
To mitigate CVE-2014-2717, upgrade to Honeywell FALCON XLWeb Linux controller version 2.04.02 or later, or FALCON XLWeb XLWebExe version 2.02.12 or later.
What are the consequences of CVE-2014-2717?
Exploitation of CVE-2014-2717 allows unauthorized remote access, potentially resulting in complete administrative control over the affected devices.
Who is affected by CVE-2014-2717?
Users of Honeywell FALCON XLWeb Linux controller versions 2.04.01 and earlier, and FALCON XLWeb XLWebExe versions 2.02.11 and earlier are affected by this vulnerability.
Is there a workaround for CVE-2014-2717?
While upgrading is recommended, a temporary workaround could include restricting access to the change-password page from untrusted networks.