6.5
CVE-2022-43485
- EPSS 0.04%
- Published 30.05.2023 17:15:09
- Last modified 21.11.2024 07:26:34
- Source psirt@honeywell.com
- Teams watchlist Login
- Open Login
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
Data is provided by the National Vulnerability Database (NVD)
Honeywell ≫ Onewireless Network Wireless Device Manager Firmware Version < r322.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.065 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
psirt@honeywell.com | 6.2 | 1.7 | 4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
|
CWE-330 Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.