CVE-2020-7005: CSRF
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7005?
The severity of CVE-2020-7005 is high with a severity value of 8.8.
What is the affected software of CVE-2020-7005?
The affected software of CVE-2020-7005 is Honeywell WIN-PAK version up to exclusive 4.7.2_b1072.3.4.
What is the vulnerability description of CVE-2020-7005?
CVE-2020-7005 is a cross-site request forgery vulnerability in Honeywell WIN-PAK, allowing remote execution of arbitrary code.
How can an attacker exploit CVE-2020-7005?
An attacker can exploit CVE-2020-7005 by tricking a user into clicking on a specially crafted link or opening a malicious website, which then executes arbitrary code.
Is there a fix for CVE-2020-7005?
To fix CVE-2020-7005, it is recommended to update to a version of Honeywell WIN-PAK that is not affected by this vulnerability.