7.5
CVE-2022-4240
- EPSS 0.01%
- Veröffentlicht 30.05.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:34:51
- Quelle psirt@honeywell.com
- CVE-Watchlists
- Unerledigt
Unauthenticated API allowing an attacker to obtain the information about network resources
Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Honeywell ≫ Onewireless Network Wireless Device Manager Firmware Version < r322.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.022 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| psirt@honeywell.com | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.