Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-14-175-01 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:21:36.077Z
Reserved: 2014-04-01T00:00:00
Link: CVE-2014-2717

No data.

Status : Deferred
Published: 2014-07-24T14:55:07.363
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-2717

No data.