📦

fusion_iv_rev_c

Vendor: honeywell

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 18 Total Indexed
Avg. EPSS 3.74% Exploit Prob.
Latest CVE CVE-2017-14263 Sep 11

Security Vulnerability Index

Page 1 / 2
8.1 CVSS
CVE-2017-14263
Exploit Found

Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.

EPSS: 3.74%