Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
References
Configurations
History
No history.
Information
Published : 2022-02-24 22:15
Updated : 2022-03-09 15:07
NVD link : CVE-2021-39364
Mitre link : CVE-2021-39364
CVE.ORG link : CVE-2021-39364
JSON object : View
Products Affected
honeywell
- hdzp252di_firmware
- hbw2per1
- hdzp252di
- hbw2per1_firmware
CWE
CWE-294
Authentication Bypass by Capture-replay