CVE-2022-43485

Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
References
Link Resource
https://process.honeywell.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:honeywell:onewireless_network_wireless_device_manager_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:onewireless_network_wireless_device_manager:-:*:*:*:*:*:*:*

History

06 Jun 2023, 14:20

Type Values Removed Values Added
CPE cpe:2.3:o:honeywell:onewireless_network_wireless_device_manager_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:onewireless_network_wireless_device_manager:-:*:*:*:*:*:*:*
References (MISC) https://process.honeywell.com/ - (MISC) https://process.honeywell.com/ - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Honeywell
Honeywell onewireless Network Wireless Device Manager
Honeywell onewireless Network Wireless Device Manager Firmware
CWE CWE-330

30 May 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-30 17:15

Updated : 2023-12-10 15:01


NVD link : CVE-2022-43485

Mitre link : CVE-2022-43485

CVE.ORG link : CVE-2022-43485


JSON object : View

Products Affected

honeywell

  • onewireless_network_wireless_device_manager_firmware
  • onewireless_network_wireless_device_manager
CWE
CWE-330

Use of Insufficiently Random Values