CVE-2015-2847
Honeywell Tuxedo Touch < 5.1.13.0_va - Improper Access Control via USERACCT Request Removal
Title source: llmDescription
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-server data stream.
References (1)
Core 1
Core References
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/857948
Scores
EPSS
0.0237
EPSS Percentile
81.8%
Details
CWE
CWE-284
Status
published
Products (1)
honeywell/tuxedo_touch
< 5.1.13.0_va
Published
Jul 26, 2015
Tracked Since
Feb 18, 2026