Vulnerability Description
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Hdzp252Di Firmware | 1.00.hw02.4 |
| Honeywell | Hdzp252Di | - |
| Honeywell | Hbw2Per1 Firmware | 1.000.hw01.3 |
| Honeywell | Hbw2Per1 | - |
Related Weaknesses (CWE)
References
- https://buildings.honeywell.com/content/dam/hbtbt/en/documents/downloads/SecuritVendor Advisory
- https://buildings.honeywell.com/us/en/brands/our-brands/security/support-and-resVendor Advisory
- https://www.honeywell.com/us/en/product-securityVendor Advisory
- https://buildings.honeywell.com/content/dam/hbtbt/en/documents/downloads/SecuritVendor Advisory
- https://buildings.honeywell.com/us/en/brands/our-brands/security/support-and-resVendor Advisory
- https://www.honeywell.com/us/en/product-securityVendor Advisory
FAQ
What is CVE-2021-39364?
CVE-2021-39364 is a vulnerability with a CVSS score of 7.5 (HIGH). Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
How severe is CVE-2021-39364?
CVE-2021-39364 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-39364?
Check the references section above for vendor advisories and patch information. Affected products include: Honeywell Hdzp252Di Firmware, Honeywell Hdzp252Di, Honeywell Hbw2Per1 Firmware, Honeywell Hbw2Per1.