Skip to main content

Vendor archive

honeywell CVEs

Beta · best-effort

103 CVEs tagged to vendor honeywell35 Critical, 36 High, 31 Medium, 1 Low, 0 Unrated.

CVE-2026-3611

Published Mar 12, 2026

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, secu…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2024-2422

Published May 30, 2024

LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an attacker to exec…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-2421

Published May 30, 2024

LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an attacker to ex…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-2420

Published May 30, 2024

LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51605

Published May 3, 2024

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51604

Published May 3, 2024

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51603

Published May 3, 2024

Honeywell Saia PG5 Controls Suite CAB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51602

Published May 3, 2024

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51601

Published May 3, 2024

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51600

Published May 3, 2024

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51599

Published May 3, 2024

Honeywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1841

Published Feb 29, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Access Panel (Web server modules) allows XSS Using Invalid Cha…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1309

Published Feb 13, 2024

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-5390

Published Jan 31, 2024

An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-5389

Published Jan 30, 2024

An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit co…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2023-6179

Published Nov 17, 2023

Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker could potentially exploit this vu…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3712

Published Sep 12, 2023

Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escalation.This issue affects PM43 v…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3711

Published Sep 12, 2023

Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versi…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26597

Published Jul 13, 2023

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgradi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-25770

Published Jul 13, 2023

Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on u…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 103 CVEsPage 1 of 5