First published: Tue May 30 2023(Updated: )
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
Credit: psirt@honeywell.com
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Onewireless Network Wireless Device Manager Firmware | <r322.2 | |
Honeywell Onewireless Network Wireless Device Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43485 is medium with a CVSS score of 6.5.
CVE-2022-43485 allows an attacker to manipulate claims in the client's JWT token.
OneWireless version 322.1 is affected by CVE-2022-43485.
No, the Honeywell OneWireless Network Wireless Device Manager is not vulnerable to CVE-2022-43485.
There is no known fix for CVE-2022-43485 at the moment. It is recommended to follow the vendor's security advisories and apply any patches or updates when available.