PT-2018-1571 · Honeywell · Cn51+13
Published
2018-09-11
·
Updated
2019-10-09
·
CVE-2018-14825
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Honeywell Mobile Computers CT60 versions 7.1
Honeywell Mobile Computers CN80 versions 7.1
Honeywell Mobile Computers CT40 versions 7.1
Honeywell Mobile Computers CK75 versions 6.0
Honeywell Mobile Computers CN75 versions 6.0
Honeywell Mobile Computers CN75e versions 6.0
Honeywell Mobile Computers CT50 versions 6.0
Honeywell Mobile Computers D75e versions 6.0
Honeywell Mobile Computers CT50 versions 4.4
Honeywell Mobile Computers D75e versions 4.4
Honeywell Mobile Computers CN51 versions 6.0
Honeywell Mobile Computers EDA50k versions 4.4
Honeywell Mobile Computers EDA50 versions 7.1
Honeywell Mobile Computers EDA50k versions 7.1
Honeywell Mobile Computers EDA70 versions 7.1
Honeywell Mobile Computers EDA60k versions 7.1
Honeywell Mobile Computers EDA51 versions 8.1
Description
The issue is related to privilege management errors in the operating system of Honeywell industrial portable computers. Exploitation of this issue could allow a remote attacker to elevate their privileges using a specially crafted application. This could enable the attacker to obtain access to sensitive information such as keystrokes, passwords, personal identifiable information, photos, emails, or business-critical documents.
Recommendations
For CT60 version 7.1, update the operating system to a version that includes the fix for this issue.
For CN80 version 7.1, update the operating system to a version that includes the fix for this issue.
For CT40 version 7.1, update the operating system to a version that includes the fix for this issue.
For CK75 version 6.0, update the operating system to a version that includes the fix for this issue.
For CN75 version 6.0, update the operating system to a version that includes the fix for this issue.
For CN75e version 6.0, update the operating system to a version that includes the fix for this issue.
For CT50 version 6.0, update the operating system to a version that includes the fix for this issue.
For D75e version 6.0, update the operating system to a version that includes the fix for this issue.
For CT50 version 4.4, update the operating system to a version that includes the fix for this issue.
For D75e version 4.4, update the operating system to a version that includes the fix for this issue.
For CN51 version 6.0, update the operating system to a version that includes the fix for this issue.
For EDA50k version 4.4, update the operating system to a version that includes the fix for this issue.
For EDA50 version 7.1, update the operating system to a version that includes the fix for this issue.
For EDA50k version 7.1, update the operating system to a version that includes the fix for this issue.
For EDA70 version 7.1, update the operating system to a version that includes the fix for this issue.
For EDA60k version 7.1, update the operating system to a version that includes the fix for this issue.
For EDA51 version 8.1, update the operating system to a version that includes the fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ck75
Cn51
Cn75
Cn75E
Cn80
Ct40
Ct50
Ct60
D75E
Eda50
Eda50K
Eda51
Eda60K
Eda70