We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-6179

Incorrect Permission assignment to program executable folders



AssignerHoneywell
Reserved2023-11-16
Published2023-11-17
Updated2024-09-04

Description

Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker could potentially exploit this vulnerability, leading to a standard user to have arbitrary system code execution. Honeywell recommends updating to the most recent version of this product, service or offering (Pro-watch 6.0.2, 6.0, 5.5.2,5.0.5).



HIGH: 7.8CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-732 Incorrect Permission Assignment for Critical Resource

Product status

Default status
0x4004f37860

4.5
affected

6.0.2
unaffected

6.0
unaffected

5.5.2
unaffected

5.0.5
unaffected

References

https://buildings.honeywell.com/us/en/brands/our-brands/security/support-and-resources/product-resources/eol-and-security-notices

https://www.honeywell.com/us/en/product-security

cve.org CVE-2023-6179

nvd.nist.gov CVE-2023-6179

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-6179
Subscribe to our newsletter to learn more about our work.