CVE-2020-6960: SQL Injection
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MAXPRO VMSto a version that resolves this vulnerability.Fixed in VMS560 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO VMS:HNMSWVMSto a version that resolves this vulnerability.Fixed in VMS560 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO VMSLTto a version that resolves this vulnerability.Fixed in VMS560 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO NVR XEto a version that resolves this vulnerability.Fixed in NVR 5.6 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO NVR SEto a version that resolves this vulnerability.Fixed in NVR 5.6 Build 595 T2-Patch - Upgrade
Upgrade
MAXPRO NVR PEto a version that resolves this vulnerability.Fixed in NVR 5.6 Build 595 T2-Patch - Upgrade
Upgrade
MPNVRSWXXto a version that resolves this vulnerability.Fixed in NVR 5.6 Build 595 T2-Patch
Event History
Frequently Asked Questions
What is CVE-2020-6960?
CVE-2020-6960 is a critical vulnerability affecting Honeywell MAXPRO VMS and NVR products.
Which versions of MAXPRO VMS and NVR are affected by CVE-2020-6960?
The following versions are affected: MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch.
What is the severity of CVE-2020-6960?
CVE-2020-6960 has a severity rating of critical (9.8).
How can I fix CVE-2020-6960?
To fix CVE-2020-6960, it is recommended to update MAXPRO VMS and NVR products to at least Version VMS560 Build 595 T2-Patch.
Where can I find more information about CVE-2020-6960?
You can find more information about CVE-2020-6960 on the official US-CERT website: https://www.us-cert.gov/ics/advisories/icsa-20-021-01