Vulnerability Description
In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Ip-Ak2 Firmware | < 1.04.07 |
| Honeywell | Ip-Ak2 | - |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/icsa-19-297-02Third Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-19-297-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2019-13525?
CVE-2019-13525 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without...
How severe is CVE-2019-13525?
CVE-2019-13525 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13525?
Check the references section above for vendor advisories and patch information. Affected products include: Honeywell Ip-Ak2 Firmware, Honeywell Ip-Ak2.