SecurityWorldMarket

25/09/2019

Honeywell identifies cyber vulnerabilities

Charlotte, NC (USA)

Honeywell Commercial Security have notified their partners that they recently received a report of potential cyber security vulnerabilities, IP Camera Unauthenticated Access to Audio, IP Camera Denial of Service & IP Camera and Recorder Replay Attack, which may affect some Honeywell video devices.

In the notification the company attaches a list of the products concerned and urges users and customers of those products to take immediate action to mitigate any potential risk.

According to Honeywell, the IP Camera Unauthenticated Access to Audio vulnerability has been reported as a “Video talk unauthorised download” issue. It may be used by hackers to download the audio stream remotely from an impacted video device.

The IP Camera Denial of Service vulnerability has been reported as a “camera stops working once it receives a crafted HTTP request” issue. It may be used by hackers to stop camera service remotely.

The IP Camera and Recorder Replay Attack vulnerability has been reported as “a weak authentication method is retained for compatibility with legacy products” issue. It may be used by hackers to remotely obtain the video device access rights by capturing the authentication information between IP camera and recorder.

Honeywell also supplies a download link in the letter to access a set of instructions that can be used to upgrade to the latest firmware version, which they say, fixes the vulnerability of the listed products and they also recommend that customers regularly check in with them on line for updates.


Tags


Product Suppliers
Back to top