Wed. Jul 6th, 2022


Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.

Reference Links(if available):

  • CVSS Score (if available)

    v2: / HIGHAV:N/AC:L/Au:N/C:N/I:P/A:P

    v3: / HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

    Links to Exploits(if available)