First published: Tue Mar 24 2020(Updated: )
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell WIN-PAK | <4.7.2_b1072.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6978 is a vulnerability in Honeywell WIN-PAK 4.7.2 Web and prior versions, due to the usage of old jQuery libraries.
The severity of CVE-2020-6978 is high with a score of 7.2.
CVE-2020-6978 affects Honeywell WIN-PAK 4.7.2 Web and prior versions by making it vulnerable due to the usage of old jQuery libraries.
To fix CVE-2020-6978, it is recommended to update to a newer version of Honeywell WIN-PAK that does not use the vulnerable jQuery libraries.
More information about CVE-2020-6978 can be found at the US-CERT advisory: https://www.us-cert.gov/ics/advisories/icsa-20-056-05