Honeywell Update
2886Warning Date
Severity Level
Warning Number
Target Sector
24 February, 2020
● Critical
2020-951
All
Description:
Honeywell has released security update to address multiple vulnerabilities in the following product:
- Notifier Web Server (NWS)
- Version 3.50 and earlier
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Authentication bypass by a capture-replay attack.
- Read files and directories by bypassing access to restricted location.
Best practice and Recommendations:
The CERT team encourages users to review Honeywell security advisory and apply the necessary update: