CVE-2019-13523
Last modified
CVE-2019-13523 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. EPSS estimates a 1.83% chance of exploitation in the next 30 days.
Description
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Hbd3pr2 Firmware | All versions |
| Honeywell | H4d3prv3 Firmware | All versions |
| Honeywell | Hed3pr3 Firmware | All versions |
| Honeywell | H4d3prv2 Firmware | All versions |
| Honeywell | Hbd3pr1 Firmware | All versions |
| Honeywell | H4w8pr2 Firmware | All versions |
| Honeywell | Hbw8pr2 Firmware | All versions |
| Honeywell | H2w2pc1m Firmware | All versions |
| Honeywell | H2w4per3 Firmware | All versions |
| Honeywell | H2w2per3 Firmware | All versions |
| Honeywell | Hew2per3 Firmware | All versions |
| Honeywell | Hew4per3b Firmware | All versions |
| Honeywell | Hbw2per1 Firmware | All versions |
| Honeywell | Hew4per2 Firmware | All versions |
| Honeywell | Hew4per2b Firmware | All versions |
| Honeywell | Hew2per2 Firmware | All versions |
| Honeywell | H4w2per2 Firmware | All versions |
| Honeywell | Hbw2per2 Firmware | All versions |
| Honeywell | H4w2per3 Firmware | All versions |
| Honeywell | Hpw2p1 Firmware | All versions |
| Honeywell | Hen08104 Firmware | All versions |
| Honeywell | Hen08144 Firmware | All versions |
| Honeywell | Hen081124 Firmware | All versions |
| Honeywell | Hen16104 Firmware | All versions |
| Honeywell | Hen16144 Firmware | All versions |
| Honeywell | Hen16184 Firmware | All versions |
| Honeywell | Hen16204 Firmware | All versions |
| Honeywell | Hen162244 Firmware | All versions |
| Honeywell | Hen16284 Firmware | All versions |
| Honeywell | Hen16304 Firmware | All versions |
| Honeywell | Hen16384 Firmware | All versions |
| Honeywell | Hen32104 Firmware | All versions |
| Honeywell | Hen321124 Firmware | All versions |
| Honeywell | Hen32204 Firmware | All versions |
| Honeywell | Hen32284 Firmware | All versions |
| Honeywell | Hen322164 Firmware | All versions |
| Honeywell | Hen32304 Firmware | All versions |
| Honeywell | Hen32384 Firmware | All versions |
| Honeywell | Hen323164 Firmware | All versions |
| Honeywell | Hen64204 Firmware | All versions |
| Honeywell | Hen64304 Firmware | All versions |
| Honeywell | Hen643164 Firmware | All versions |
| Honeywell | Hen643324 Firmware | All versions |
| Honeywell | Hen643484 Firmware | All versions |
| Honeywell | Hen04103 Firmware | All versions |
| Honeywell | Hen04113 Firmware | All versions |
| Honeywell | Hen04123 Firmware | All versions |
| Honeywell | Hen08103 Firmware | All versions |
| Honeywell | Hen08113 Firmware | All versions |
| Honeywell | Hen08123 Firmware | All versions |
Showing 50 of 59 affected configurations. See NVD for the full list.
References
- https://www.us-cert.gov/ics/advisories/icsa-19-260-03Mitigation, Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-19-260-03Mitigation, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13523?
How severe is CVE-2019-13523?
How do I fix CVE-2019-13523?
Are you affected by CVE-2019-13523?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
