First published: Mon Feb 13 2017(Updated: )
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell XL Web II controller | =xlwebexe-1-02-08 | |
Honeywell XL Web II controller | =xlwebexe-2-01-00 | |
Honeywell XL Web II controller |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5140 has a medium severity due to the risk of exposing sensitive information through stored clear text passwords.
To fix CVE-2017-5140, it is recommended to upgrade the Honeywell XL Web II controller to the latest version where passwords are not stored in clear text.
CVE-2017-5140 affects Honeywell XL Web II controllers with specific versions of XLWebExe-1-02-08 and XLWebExe-2-01-00.
CVE-2017-5140 could be potentially exploited remotely if an attacker has access to the affected systems and can retrieve the stored passwords.
The impact of CVE-2017-5140 includes unauthorized access to systems and data due to the lack of password encryption.