CVE-2019-13525
Last modified
CVE-2019-13525 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Ip-Ak2 Firmware | < 1.04.07 |
References
- https://www.us-cert.gov/ics/advisories/icsa-19-297-02Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-19-297-02Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13525?
How severe is CVE-2019-13525?
How do I fix CVE-2019-13525?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1352A remote code execution vulnerability exists when Git for Vi…8.8
- CVE-2019-13520Multiple buffer overflow issues have been identified in Alph…7.8
- CVE-2019-13521A maliciously crafted program file opened by an unsuspecting…7.8
- CVE-2019-13522An attacker could use a specially crafted project file to co…7.8
- CVE-2019-13523In Honeywell Performance IP Cameras and Performance NVRs, th…5.3
- CVE-2019-13524GE PACSystems RX3i CPE100/115: All versions prior to R9.85,C…7.5
- CVE-2019-13526Datalogic AV7000 Linear barcode scanner all versions prior t…
- CVE-2019-13527In Rockwell Automation Arena Simulation Software Cat. 9502-A…7.8
- CVE-2019-13528A specific utility may allow an attacker to gain read access…4.4
- CVE-2019-13529An attacker could send a malicious link to an authenticated …8.8
- CVE-2019-1353An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, …9.8
- CVE-2019-13530Philips IntelliVue WLAN, portable patient monitors, WLAN Ver…7.2
Are you affected by CVE-2019-13525?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
