Your review has been sent successfully

Honeywell Updates

2914
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

22 January, 2020

● Critical

2020-828

Energy - Manufacturing - Commercial Facilities

Description:

Honeywell has released security updates to address vulnerabilities in the following products:

MAXPRO VMS:

  • HNMSWVMS prior to Version VMS560 Build 595 T2-Patch
  • HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch

MAXPRO NVR:

  • MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch
  • MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch
  • MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch
  • MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • SQL Injection
  • Elevation of privileges
  • Remote code execution
  • Denial-of-service (DoS)

Best practice and Recommendations:

The CERT team encourages users to review Honeywell security advisory and apply the necessary updates:

Last updated at 22 January, 2020

Rate the content

rate-icon
up icon