This page lists publicly disclosed CVE vulnerabilities affecting honeywell win-pak (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2021-47868 | WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the WPCommandFileService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files <x86>\WINPAKPRO\WPCommandFileService Service.exe to inject malicious code that would execute with LocalSystem permissions. | [email protected] | 8.5 | 0.13% | 2026-01-21 | 2026-06-17 |
| CVE-2021-47866 | WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the GuardTourService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files <x86>\WINPAKPRO\WP GuardTour Service.exe to inject malicious code that would execute during service startup. | [email protected] | 8.5 | 0.13% | 2026-01-21 | 2026-06-17 |
| CVE-2020-6982 | In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution. | [email protected] | 8.8 | 1.05% | 2020-03-24 | 2026-06-16 |
| CVE-2020-6978 | In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries. | [email protected] | 7.2 | 0.78% | 2020-03-24 | 2026-06-16 |
| CVE-2020-7005 | In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code. | [email protected] | 8.8 | 0.90% | 2020-03-24 | 2026-06-16 |