CVE-2020-7005: Honeywell Win-Pak

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.

Affected products

  • Honeywell Win-Pak: before 4.7.2_b1072.3.4 (fixed in 4.7.2_b1072.3.4)

Published 2020-03-24. Last modified 2026-06-17.