Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
References
Information
Published : 2022-02-24 14:15
Updated : 2022-03-09 07:07
NVD link : CVE-2021-39364
Mitre link : CVE-2021-39364
JSON object : View
CWE
CWE-294
Authentication Bypass by Capture-replay
Products Affected
honeywell
- hdzp252di_firmware
- hbw2per1
- hbw2per1_firmware
- hdzp252di