CVE Vulnerabilities

CVE-2014-2717

Published: Jul 24, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.

Affected Software

NameVendorStart VersionEnd Version
Falcon_xlweb_linux_controllerHoneywell*2.04.01 (including)
Falcon_xlweb_xlwebexeHoneywell*2.02.11 (including)

References