First published: Thu Feb 24 2022(Updated: )
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Hdzp252di Firmware | =1.00.hw02.4 | |
Honeywell HDZP252DI | ||
Honeywell Hbw2per1 Firmware | =1.000.hw01.3 | |
Honeywell Hbw2per1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39364 is a vulnerability that allows command spoofing for camera control on Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices after ARP cache poisoning.
CVE-2021-39364 has a severity rating of 7.5 (high).
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices are affected by CVE-2021-39364.
Command spoofing can be achieved on the affected devices after ARP cache poisoning.
To fix CVE-2021-39364, it is recommended to refer to the vendor's security notification and follow their recommended actions.