First published: Thu Jul 24 2014(Updated: )
Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Falcon XLWeb | <=2.04.01 | |
Honeywell FALCON XLWeb Linux controller | <=2.02.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2717 is classified as a critical vulnerability due to its potential for remote attacker exploitation.
To mitigate CVE-2014-2717, upgrade to Honeywell FALCON XLWeb Linux controller version 2.04.02 or later, or FALCON XLWeb XLWebExe version 2.02.12 or later.
Exploitation of CVE-2014-2717 allows unauthorized remote access, potentially resulting in complete administrative control over the affected devices.
Users of Honeywell FALCON XLWeb Linux controller versions 2.04.01 and earlier, and FALCON XLWeb XLWebExe versions 2.02.11 and earlier are affected by this vulnerability.
While upgrading is recommended, a temporary workaround could include restricting access to the change-password page from untrusted networks.