6.5
CVE-2022-43485
- EPSS 0.04%
- Veröffentlicht 30.05.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:26:34
- Quelle psirt@honeywell.com
- CVE-Watchlists
- Unerledigt
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Honeywell ≫ Onewireless Network Wireless Device Manager Firmware Version < r322.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.095 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| psirt@honeywell.com | 6.2 | 1.7 | 4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
|
CWE-330 Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.