PatchSiren cyber security CVE debrief
CVE-2017-5142 Honeywell CVE debrief
CVE-2017-5142 is a critical Honeywell XL Web II / XLWeb 500 controller issue where a low-privileged user can access a specific URL to open and change parameters because of improper privilege management. The published CVSS 3.0 vector indicates network accessibility, low attack complexity, low privileges required, no user interaction, and impact to confidentiality, integrity, and availability.
- Vendor
- Honeywell
- Product
- Unknown
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-02
- Original CVE updated
- 2017-02-02
- Advisory published
- 2017-02-02
- Advisory updated
- 2017-02-02
Who should care
Industrial control system operators, OT/ICS administrators, integrators, and security teams responsible for Honeywell XL Web II controller deployments running XLWebExe-2-01-00 or earlier, and XLWeb 500 deployments running XLWebExe-1-02-08 or earlier.
Technical summary
NVD lists affected Honeywell XL Web II controller versions XLWebExe-2-01-00 and prior, and XLWeb 500 versions XLWebExe-1-02-08 and prior. The weakness is mapped to CWE-269 (Improper Privilege Management). According to the advisory summary, a low-privileged user can reach a specific URL and modify parameters, which indicates an authorization boundary failure rather than a pure authentication problem. The CVSS vector is CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L, reflecting network reachability and meaningful impact once access is obtained.
Defensive priority
High. Because the issue is rated Critical and affects controller management functions, organizations should treat exposure of the relevant web interface as urgent and restrict access until vendor guidance and compensating controls are in place.
Recommended defensive actions
- Identify any Honeywell XL Web II or XLWeb 500 deployments and verify whether they are running XLWebExe-2-01-00 or earlier, or XLWebExe-1-02-08 or earlier.
- Restrict network access to the controller web interface to only trusted administrative hosts and management segments.
- Review controller authorization settings and confirm that low-privileged accounts cannot reach parameter-editing URLs.
- Apply the vendor and ICS-CERT guidance referenced in the official advisory for mitigation steps and update planning.
- Monitor for unauthorized parameter changes or unexpected web requests against the controller management interface.
- If remediation cannot be applied immediately, use compensating controls such as segmentation, access control lists, and administrative account review to reduce exposure.
Evidence notes
The description, affected versions, and CWE mapping come from the supplied NVD record for CVE-2017-5142. The advisory references include the US-CERT/ICS-CERT bulletin ICSA-17-033-01 and the SecurityFocus BID 95971 entry. The CVSS vector supplied in the source item supports the severity and access characteristics stated here. No exploit steps or unsupported remediation claims are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5142 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5142
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5142 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5142
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSA-17-033-01
[email protected] - Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.