CVE-2017-5140: Critical severity Honeywell XL Web II controller vulnerability
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5140?
CVE-2017-5140 has a medium severity due to the risk of exposing sensitive information through stored clear text passwords.
How do I fix CVE-2017-5140?
To fix CVE-2017-5140, it is recommended to upgrade the Honeywell XL Web II controller to the latest version where passwords are not stored in clear text.
What products are affected by CVE-2017-5140?
CVE-2017-5140 affects Honeywell XL Web II controllers with specific versions of XLWebExe-1-02-08 and XLWebExe-2-01-00.
Is CVE-2017-5140 exploitable remotely?
CVE-2017-5140 could be potentially exploited remotely if an attacker has access to the affected systems and can retrieve the stored passwords.
What impact does CVE-2017-5140 have on security?
The impact of CVE-2017-5140 includes unauthorized access to systems and data due to the lack of password encryption.