CVE-2021-39363: Command Injection
Published Feb 24, 2022
·Updated
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.
Affected Software
4 affected components
Honeywell Hdzp252di Firmware=1.00.hw02.4
Honeywell HDZP252DI
Honeywell Hbw2per1 Firmware=1.000.hw01.3
Honeywell HBW2PER1
Event History
Feb 24, 2022
CVE Published
via MITRE·09:13 PM
Data Sourced
via MITRE·09:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-39363?
The severity of CVE-2021-39363 is critical with a CVSS score of 9.8.
2
How can Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices be affected by CVE-2021-39363?
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices can be affected by a video replay attack after ARP cache poisoning is achieved.
3
Can Honeywell HDZP252DI 1.00.HW02.4 device be affected by CVE-2021-39363?
Yes, Honeywell HDZP252DI 1.00.HW02.4 device can be affected by CVE-2021-39363.
4
Can Honeywell HBW2PER1 1.000.HW01.3 device be affected by CVE-2021-39363?
Yes, Honeywell HBW2PER1 1.000.HW01.3 device can be affected by CVE-2021-39363.
5
How can I mitigate the vulnerability described in CVE-2021-39363?
Refer to the official Honeywell security notification and follow the recommended mitigation steps.