CVE-2022-43485

Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
References
Link Resource
https://process.honeywell.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:honeywell:onewireless_network_wireless_device_manager_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:onewireless_network_wireless_device_manager:-:*:*:*:*:*:*:*

History

06 Jun 2023, 14:20

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Honeywell onewireless Network Wireless Device Manager
Honeywell
Honeywell onewireless Network Wireless Device Manager Firmware
CWE CWE-330
CPE cpe:2.3:o:honeywell:onewireless_network_wireless_device_manager_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:onewireless_network_wireless_device_manager:-:*:*:*:*:*:*:*
References (MISC) https://process.honeywell.com/ - (MISC) https://process.honeywell.com/ - Product

30 May 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-30 17:15

Updated : 2024-02-28 20:13


NVD link : CVE-2022-43485

Mitre link : CVE-2022-43485

CVE.ORG link : CVE-2022-43485


JSON object : View

Products Affected

honeywell

  • onewireless_network_wireless_device_manager
  • onewireless_network_wireless_device_manager_firmware
CWE
CWE-330

Use of Insufficiently Random Values