CVE-2020-6974: Honeywell Notifier Webserver

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem.

Affected products

  • Honeywell Notifier Webserver: up to and including 3.50

Published 2020-04-07. Last modified 2026-06-17.