CVE-2017-5143: Path Traversal
Published Feb 13, 2017
·Updated
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal attack by accessing a specific URL.
Affected Software
6 affected components
Honeywell XL Web II controller=xlwebexe-1-02-08
Honeywell XL Web II controller=xlwebexe-2-01-00
Honeywell XL Web II controller
All of the following
Any of the following
Honeywell XL Web II controller=xlwebexe-1-02-08
Honeywell XL Web II controller=xlwebexe-2-01-00
Honeywell XL Web II controller
Event History
Feb 13, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5143?
CVE-2017-5143 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-5143?
To fix CVE-2017-5143, users should update their Honeywell XL Web II controller to versions XLWebExe-2-01-01 or XLWebExe-1-02-09 or later.
3
What type of attack is possible with CVE-2017-5143?
CVE-2017-5143 allows for a directory traversal attack without user authentication.
4
Which versions of Honeywell XL Web II controller are affected by CVE-2017-5143?
CVE-2017-5143 affects versions XLWebExe-1-02-08 and earlier, as well as XLWebExe-2-01-00 and earlier.
5
Is CVE-2017-5143 related to any specific hardware?
Yes, CVE-2017-5143 is related to the Honeywell XL Web II controller.