Severity
Medium
Analysis Summary
The integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.
Impact
Missing Authentication for Critical Function
Affected Vendors
Honeywell
Affected Products
IP-AK2 Access Control Panel Version 1.04.07 and prior
Remediation
Honeywell released new firmware Version 1.04.15 and recommends affected users to contact customer support to resolve the issue.