CVE-2021-39364

HIGH

Honeywell HDZP252DI <1.00.HW02.4 & HBW2PER1 <1.000.HW01.3 - Command...

Title source: llm

Description

Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.

Scores

CVSS v3 7.5
EPSS 0.0023
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-294
Status published

Affected Products (2)

honeywell/hdzp252di_firmware
honeywell/hbw2per1_firmware

Timeline

Published Feb 24, 2022
Tracked Since Feb 18, 2026