Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
References
Configurations
History
No history.
Information
Published : 2022-02-24 22:15
Updated : 2024-02-28 19:09
NVD link : CVE-2021-39364
Mitre link : CVE-2021-39364
CVE.ORG link : CVE-2021-39364
JSON object : View
Products Affected
honeywell
- hbw2per1_firmware
- hdzp252di
- hdzp252di_firmware
- hbw2per1
CWE
CWE-294
Authentication Bypass by Capture-replay