CVE-2019-18230 describes a vulnerability in multiple versions of Honeywell equIP and Performance series IP cameras, allowing unauthenticated access to audio streams over HTTP. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, enabling remote attackers to achieve high confidentiality impact by eavesdropping on audio. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for unauthorized audio surveillance remains a significant concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.000.hw01.3.20190820CPE matchmatch criteria | cpe:2.3:o:honeywell:h4d8pr1_firmware:*:*:*:*:*:*:*:* | ||
< 1.000.hw01.1.20190822CPE matchmatch criteria | cpe:2.3:o:honeywell:hfd5pr1_firmware:*:*:*:*:*:*:*:* | ||
< 1.000.hw01.3.20190820CPE matchmatch criteria | cpe:2.3:o:honeywell:hpw2p1_firmware:*:*:*:*:*:*:*:* | ||
< 1.000.hw10.5.20190812CPE matchmatch criteria | cpe:2.3:o:honeywell:hdzp304di_firmware:*:*:*:*:*:*:*:* | ||
< 1.000.hw02.3.20181109CPE matchmatch criteria | cpe:2.3:o:honeywell:hdzp252di_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.