Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xff-6366-vrm2

Опубликовано: 06 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 9.1

Описание

Honeywell OneWireless

Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to

R322.3, R330.2 or the most recent version of this product2.

Honeywell OneWireless

Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to

R322.3, R330.2 or the most recent version of this product2.

EPSS

Процентиль: 80%
0.01394
Низкий

9.4 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

nvd
около 1 года назад

Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to R322.3, R330.2 or the most recent version of this product2.

EPSS

Процентиль: 80%
0.01394
Низкий

9.4 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-77