CISA has released an advisory on deserialization of untrusted data and SQL injection vulnerabilities in Honeywell MAXPRO VMS & NVR. Multiple products and versions of these products are affected. Successful exploitation of these vulnerabilities could result in elevation of privileges, cause a denial-of-service condition, or allow unauthenticated remote code execution. Honeywell recommends users update VMS 560 Build 595 T2-Patch for affected VMS systems, and NVR 5.6 Build 595 T2-Patch for affected NVR systems. CISA also recommends a series of measures to mitigate the vulnerability. Read the advisory at CISA.
You are here
Related Resources
Jan 16, 2025 in Cybersecurity, in OT-ICS Security, in Security Preparedness
Jan 16, 2025 in Cybersecurity, in OT-ICS Security, in Federal & State Resources
Jan 16, 2025 in Cybersecurity, in Federal & State Resources, in Security Preparedness