First published: Tue May 30 2023(Updated: )
An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in version 322.2.
Credit: psirt@honeywell.com
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Onewireless Network Wireless Device Manager Firmware | <r322.2 | |
Honeywell Onewireless Network Wireless Device Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-46361 is medium (6.8).
An attacker can exploit CVE-2022-46361 by plugging a USB device into the WDM and executing unwanted commands.
All versions up to r322.2 of OneWireless are affected by CVE-2022-46361.
CVE-2022-46361 has CWE IDs 78 and 77.
You can find more information about CVE-2022-46361 at the following link: [https://process.honeywell.com/](https://process.honeywell.com/)