CVE Feed

    Dashboard / CVE / CVE-2017-14263

    CVE-2017-14263

    Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.

    Published:Sep 11, 2017
    Last Modified:Apr 20, 2025
    EPS:Sep 11, 2017
    EPSS Score:0.24422
    CVSS Score:8.1

    Affected Products

    Vendor
    Honeywell
    Product
    Enterprise Dvr
    Vendor
    Honeywell
    Product
    Enterprise Dvr Firmware
    Vendor
    Honeywell
    Product
    Fusion Iv Rev C
    Vendor
    Honeywell
    Product
    Fusion Iv Rev C Firmware
    Vendor
    Honeywell
    Product
    Maxpro Nvr Hybrid Se
    Vendor
    Honeywell
    Product
    Maxpro Nvr Hybrid Se Firmware
    Vendor
    Honeywell
    Product
    Maxpro Nvr Hybrid Xe
    Vendor
    Honeywell
    Product
    Maxpro Nvr Hybrid Xe Firmware
    Vendor
    Honeywell
    Product
    Maxpro Nvr Pe
    Vendor
    Honeywell
    Product
    Maxpro Nvr Pe Firmware
    Vendor
    Honeywell
    Product
    Maxpro Nvr Se
    Vendor
    Honeywell
    Product
    Maxpro Nvr Se Firmware
    Vendor
    Honeywell
    Product
    Maxpro Nvr Xe
    Vendor
    Honeywell
    Product
    Maxpro Nvr Xe Firmware

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High