CVE-2019-18230

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
31/10/2019
Last modified:
05/11/2019

Description

Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:honeywell:h4d8pr1_firmware:*:*:*:*:*:*:*:* 1.000.hw01.3.20190820 (excluding)
cpe:2.3:h:honeywell:h4d8pr1:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:hfd5pr1_firmware:*:*:*:*:*:*:*:* 1.000.hw01.1.20190822 (excluding)
cpe:2.3:h:honeywell:hfd5pr1:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:hpw2p1_firmware:*:*:*:*:*:*:*:* 1.000.hw01.3.20190820 (excluding)
cpe:2.3:h:honeywell:hpw2p1:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:hdzp304di_firmware:*:*:*:*:*:*:*:* 1.000.hw10.5.20190812 (excluding)
cpe:2.3:h:honeywell:hdzp304di:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:hdzp252di_firmware:*:*:*:*:*:*:*:* 1.000.hw02.3.20181109 (excluding)
cpe:2.3:h:honeywell:hdzp252di:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:hdz302din-s1_firmware:*:*:*:*:*:*:*:* 1.000.0041.20180530 (excluding)
cpe:2.3:h:honeywell:hdz302din-s1:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:hdz302lik_firmware:*:*:*:*:*:*:*:* 1.000.61.1.20180607 (excluding)
cpe:2.3:h:honeywell:hdz302lik:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:hdz302liw_firmware:*:*:*:*:*:*:*:* 1.000.61.1.20180607 (excluding)


References to Advisories, Solutions, and Tools