First published: Tue Sep 13 2022(Updated: )
A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell SoftMaster | =4.51 | |
Honeywell SoftMaster: version 4.51 |
Honeywell has released firmware update packages for the affected products on their website. More information can be found in the Honeywell Security Notification SN2022-08-31 01 SoftMaster-R4.7
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2022-2332.
The severity of CVE-2022-2332 is high, with a severity value of 7.8.
Honeywell SoftMaster version 4.51 is affected by CVE-2022-2332.
An unprivileged attacker can escalate to administrator privileges in Honeywell SoftMaster version 4.51 due to insecure permission assignment.
Yes, you can find more information about CVE-2022-2332 in the following references: [link1](https://www.cisa.gov/uscert/ics/advisories/icsa-22-256-02), [link2](https://www.security.honeywell.com/-/media/Security/Resources/PDF/Product-Warranty/Security_Notification_SN_2019-09-13-02_V4-pdf.pdf).