CVE-2020-6972: Critical severity Honeywell Notifier Webserver vulnerability
Published Mar 24, 2020
·Updated
In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.
Affected Software
1 affected component
Honeywell Notifier Webserver<=3.50
Event History
Mar 24, 2020
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-6972.
2
What is the severity of CVE-2020-6972?
CVE-2020-6972 has a severity of 9.1 (Critical).
3
Which software versions are affected by CVE-2020-6972?
Versions of Notifier Web Server (NWS) up to and including 3.50 are affected by CVE-2020-6972.
4
How can the authentication bypass vulnerability be exploited?
The authentication bypass vulnerability in CVE-2020-6972 can be exploited through a capture-replay attack from a web browser.
5
Is there a fix available for CVE-2020-6972?
At the moment, there is no information available about a fix for CVE-2020-6972. It is recommended to monitor the vendor's website for any updates or patches.