CVE-2020-6978: High severity Honeywell WIN-PAK vulnerability
Published Mar 24, 2020
·Updated
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.
Affected Software
1 affected component
Honeywell WIN-PAK<4.7.2_b1072.3.4
Event History
Mar 24, 2020
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-6978?
CVE-2020-6978 is a vulnerability in Honeywell WIN-PAK 4.7.2 Web and prior versions, due to the usage of old jQuery libraries.
2
What is the severity of CVE-2020-6978?
The severity of CVE-2020-6978 is high with a score of 7.2.
3
How does CVE-2020-6978 affect the Honeywell WIN-PAK software?
CVE-2020-6978 affects Honeywell WIN-PAK 4.7.2 Web and prior versions by making it vulnerable due to the usage of old jQuery libraries.
4
How can I fix CVE-2020-6978?
To fix CVE-2020-6978, it is recommended to update to a newer version of Honeywell WIN-PAK that does not use the vulnerable jQuery libraries.
5
Where can I find more information about CVE-2020-6978?
More information about CVE-2020-6978 can be found at the US-CERT advisory: https://www.us-cert.gov/ics/advisories/icsa-20-056-05