CVE-2015-2847

Honeywell Tuxedo Touch < 5.1.13.0_va - Improper Access Control via USERACCT Request Removal

Title source: llm
STIX 2.1

Description

Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-server data stream.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/857948

Scores

EPSS 0.0237
EPSS Percentile 81.8%

Details

CWE
CWE-284
Status published
Products (1)
honeywell/tuxedo_touch < 5.1.13.0_va
Published Jul 26, 2015
Tracked Since Feb 18, 2026