CVE-2019-13525
Summary
| CVE | CVE-2019-13525 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-25 18:15:00 UTC |
| Updated | 2019-10-30 18:25:00 UTC |
| Description | In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Honeywell | Ip-ak2 | - | All | All | All |
| Hardware | Honeywell | Ip-ak2 | - | All | All | All |
| Operating System | Honeywell | Ip-ak2 Firmware | All | All | All | All |
| Operating System | Honeywell | Ip-ak2 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Honeywell IP-AK2 | CISA | MISC | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.