CVE-2020-6959: Critical severity Honeywell Maxpro Nvr Xe Firmware vulnerability
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MAXPRO VMSto a version that resolves this vulnerability.Fixed in VMS560 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO VMS:HNMSWVMSto a version that resolves this vulnerability.Fixed in VMS560 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO VMS:HNMSWVMSLTto a version that resolves this vulnerability.Fixed in VMS560 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO NVR XEto a version that resolves this vulnerability.Fixed in NVR 5.6 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO NVR SEto a version that resolves this vulnerability.Fixed in NVR 5.6 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO NVR PEto a version that resolves this vulnerability.Fixed in NVR 5.6 Build 595 T2-Patch - Upgrade
Upgrade
MPNVRSWXXto a version that resolves this vulnerability.Fixed in NVR 5.6 Build 595 T2-Patch
Event History
Frequently Asked Questions
What is CVE-2020-6959?
CVE-2020-6959 is a vulnerability in MAXPRO VMS and NVR software versions prior to Version VMS560 Build 595 T2-Patch.
What is the severity of CVE-2020-6959?
CVE-2020-6959 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2020-6959?
MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, Honeywell Mpnvrswxx Firmware versions up to and including 5.6, Honeywell Hnmswvms Firmware versions up to and including vms560, and Honeywell Hnmswvmslt Firmware versions up to and including vms560.
How can I fix CVE-2020-6959?
To fix CVE-2020-6959, users should update their MAXPRO VMS and NVR software to at least Version VMS560 Build 595 T2-Patch or Version NVR 5.6 Build 595 T2-Patch, depending on the affected product.
Where can I find more information about CVE-2020-6959?
You can find more information about CVE-2020-6959 at the following link: [https://www.us-cert.gov/ics/advisories/icsa-20-021-01](https://www.us-cert.gov/ics/advisories/icsa-20-021-01).