Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.honeywell.com/us/en/product-security |
|
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Honeywell
Honeywell s35 Camera |
|
| Vendors & Products |
Honeywell
Honeywell s35 Camera |
Mon, 27 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of this product, service or offering (S35 Pinhole/Kit Camera to version 2025.08.28, S35 AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera to version 2025.08.22, S35 Thermal Camera to version 2025.08.26). | |
| Title | Inadequate access control measure allows unauthorized users to access restricted administrative functions | |
| Weaknesses | CWE-639 CWE-668 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Honeywell
Published:
Updated: 2025-10-27T16:04:11.466Z
Reserved: 2025-10-27T14:59:57.822Z
Link: CVE-2025-12351
Updated: 2025-10-27T15:14:53.431Z
Status : Deferred
Published: 2025-10-27T15:15:37.653
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-12351
No data.
OpenCVE Enrichment
Updated: 2025-10-27T22:03:48Z