First published: Tue Mar 24 2020(Updated: )
In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Notifier Webserver | <=3.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-6972.
CVE-2020-6972 has a severity of 9.1 (Critical).
Versions of Notifier Web Server (NWS) up to and including 3.50 are affected by CVE-2020-6972.
The authentication bypass vulnerability in CVE-2020-6972 can be exploited through a capture-replay attack from a web browser.
At the moment, there is no information available about a fix for CVE-2020-6972. It is recommended to monitor the vendor's website for any updates or patches.