Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2023-5878
Disclosure Date: February 06, 2025 (last updated February 07, 2025)
Honeywell OneWireless
Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to
R322.3, R330.2 or the most recent version of this product2.
0
Attacker Value
Unknown
CVE-2022-4240
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1
0
Attacker Value
Unknown
CVE-2022-46361
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in version 322.2.
0
Attacker Value
Unknown
CVE-2022-43485
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
0