CVE-2017-14263
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2017
Last modified:
20/04/2025
Description
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:honeywell:enterprise_dvr_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:honeywell:enterprise_dvr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:honeywell:maxpro_nvr_hybrid_se_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:honeywell:maxpro_nvr_hybrid_se:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:honeywell:maxpro_nvr_hybrid_xe_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:honeywell:maxpro_nvr_hybrid_xe:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:honeywell:maxpro_nvr_se_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:honeywell:maxpro_nvr_se:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:honeywell:maxpro_nvr_xe_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:honeywell:maxpro_nvr_xe:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:honeywell:fusion_iv_rev_c_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:honeywell:fusion_iv_rev_c:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:honeywell:maxpro_nvr_pe_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:honeywell:maxpro_nvr_pe:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



