Honeywell Updates
2914Warning Date
Severity Level
Warning Number
Target Sector
22 January, 2020
● Critical
2020-828
Energy - Manufacturing - Commercial Facilities
Description:
Honeywell has released security updates to address vulnerabilities in the following products:
MAXPRO VMS:
- HNMSWVMS prior to Version VMS560 Build 595 T2-Patch
- HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch
MAXPRO NVR:
- MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch
- MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch
- MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch
- MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- SQL Injection
- Elevation of privileges
- Remote code execution
- Denial-of-service (DoS)
Best practice and Recommendations:
The CERT team encourages users to review Honeywell security advisory and apply the necessary updates: