CVE-2020-6974: Path Traversal
Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6974?
CVE-2020-6974 is a vulnerability in the Honeywell Notifier Web Server (NWS) version 3.50, which allows a path traversal attack to bypass access to restricted directories.
How severe is CVE-2020-6974?
CVE-2020-6974 is considered critical with a severity score of 9.8 out of 10.
What is the affected software for CVE-2020-6974?
The affected software for CVE-2020-6974 is Honeywell Notifier Web Server (NWS) version 3.50.
How can I fix CVE-2020-6974?
To fix CVE-2020-6974, update your Honeywell Notifier Web Server (NWS) firmware to the latest version provided by Honeywell.
Where can I find more information about CVE-2020-6974?
You can find more information about CVE-2020-6974 in the advisory published by US-CERT.