Back to overview

CVE-2026-17612

MEDIUM
6.9
CVSS 4.0
Description
Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends updating to the latest available version (HC5.26.1.16.20260207) once available.

Metadata

CVE ID
CVE-2026-17612
State
PUBLISHED
Assigner
Honeywell
Reserved
2026-07-27 18:45 UTC
Published
2026-07-27 18:45 UTC
Last updated
2026-07-27 19:37 UTC
Primary CWE
CWE-200
CWE-200 - Exposure of Sensitive Information to an Unauthoriz…
Vendor / Product
Honeywell / S35 Series 3M/5M/8M/PinHole Cameras
Sources
cve.org  ·  NVD

Severity & Metrics

6.9 MEDIUM CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Honeywell S35 Series 3M/5M/8M/PinHole Cameras Linux HC4.25.1.27.20250728 ≤ HC5.26.1.14.20260207
Weakness (CWE)
CWESourceDescription
CWE-200 cna CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Back to overview