CWE
306 200
Advisory Published
Updated

CVE-2019-13523: Infoleak

First published: Thu Sep 26 2019(Updated: )

In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Honeywell Hbd3pr2 Firmware
Honeywell Hbd3pr2
Honeywell H4d3prv3 Firmware
Honeywell H4d3prv3
Honeywell Hed3pr3 Firmware
Honeywell Hed3pr3
Honeywell H4d3prv2 Firmware
Honeywell H4d3prv2
Honeywell Hbd3pr1 Firmware
Honeywell Hbd3pr1
Honeywell H4w8pr2 Firmware
Honeywell H4w8pr2
Honeywell Hbw8pr2 Firmware
Honeywell Hbw8pr2
Honeywell H2w2pc1m Firmware
Honeywell H2w2pc1m
Honeywell H2w4per3 Firmware
Honeywell H2w4per3
Honeywell H2w2per3 Firmware
Honeywell H2w2per3
Honeywell Hew2per3 Firmware
Honeywell Hew2per3
Honeywell Hew4per3b Firmware
Honeywell Hew4per3b
Honeywell Hbw2per1 Firmware
Honeywell Hbw2per1
Honeywell Hew4per2 Firmware
Honeywell Hew4per2
Honeywell Hew4per2b Firmware
Honeywell Hew4per2b
Honeywell Hew2per2 Firmware
Honeywell Hew2per2
Honeywell H4w2per2 Firmware
Honeywell H4w2per2
Honeywell Hbw2per2 Firmware
Honeywell Hbw2per2
Honeywell H4w2per3 Firmware
Honeywell H4w2per3
Honeywell Hpw2p1 Firmware
Honeywell Hpw2p1
Honeywell Hen08104 Firmware
Honeywell Hen08104
Honeywell Hen08144 Firmware
Honeywell Hen08144
Honeywell Hen081124 Firmware
Honeywell Hen081124
Honeywell Hen16104 Firmware
Honeywell Hen16104
Honeywell Hen16144 Firmware
Honeywell Hen16144
Honeywell Hen16184 Firmware
Honeywell Hen16184
Honeywell Hen16204 Firmware
Honeywell Hen16204
Honeywell Hen162244 Firmware
Honeywell Hen162244
Honeywell Hen16284 Firmware
Honeywell Hen16284
Honeywell Hen16304 Firmware
Honeywell Hen16304
Honeywell Hen16384 Firmware
Honeywell Hen16384
Honeywell Hen32104 Firmware
Honeywell Hen32104
Honeywell Hen321124 Firmware
Honeywell Hen321124
Honeywell Hen32204 Firmware
Honeywell Hen32204
Honeywell Hen32284 Firmware
Honeywell Hen32284
Honeywell Hen322164 Firmware
Honeywell Hen322164
Honeywell Hen32304 Firmware
Honeywell Hen32304
Honeywell Hen32384 Firmware
Honeywell Hen32384
Honeywell Hen323164 Firmware
Honeywell Hen323164
Honeywell Hen64204 Firmware
Honeywell Hen64204
Honeywell Hen64304 Firmware
Honeywell Hen64304
Honeywell Hen643164 Firmware
Honeywell Hen643164
Honeywell Hen643324 Firmware
Honeywell Hen643324
Honeywell Hen643484 Firmware
Honeywell Hen643484
Honeywell Hen04103 Firmware
Honeywell Hen04103
Honeywell Hen04113 Firmware
Honeywell Hen04113
Honeywell Hen04123 Firmware
Honeywell Hen04123
Honeywell Hen08103 Firmware
Honeywell Hen08103
Honeywell Hen08113 Firmware
Honeywell Hen08113
Honeywell Hen08123 Firmware
Honeywell Hen08123
Honeywell Hen08143 Firmware
Honeywell Hen08143
Honeywell Hen16103 Firmware
Honeywell Hen16103
Honeywell Hen16123 Firmware
Honeywell Hen16123
Honeywell Hen16143 Firmware
Honeywell Hen16143
Honeywell Hen16163 Firmware
Honeywell Hen16163
Honeywell Hen04103l Firmware
Honeywell Hen04103l
Honeywell Hen08103l Firmware
Honeywell Hen08103l
Honeywell Hen16103l Firmware
Honeywell Hen16103l
Honeywell Hen32103l Firmware
Honeywell Hen32103l

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203