CVE-2021-39364

HIGH

Honeywell HDZP252DI <1.00.HW02.4 & HBW2PER1 <1.000.HW01.3 - Command...

Title source: llm
STIX 2.1

Description

Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.

Scores

CVSS v3 7.5
EPSS 0.0023
EPSS Percentile 46.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-294
Status published
Products (2)
honeywell/hbw2per1_firmware 1.000.hw01.3
honeywell/hdzp252di_firmware 1.00.hw02.4
Published Feb 24, 2022
Tracked Since Feb 18, 2026