6.5
CVE-2022-43485
- EPSS 0.04%
- Veröffentlicht 30.05.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:26:34
- Quelle psirt@honeywell.com
- Teams Watchlist Login
- Unerledigt Login
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Honeywell ≫ Onewireless Network Wireless Device Manager Firmware Version < r322.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.065 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
psirt@honeywell.com | 6.2 | 1.7 | 4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
|
CWE-330 Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.