Command Injection Flaw in Honeywell OneWireless Wireless Device Manager
CVE-2023-5878

9.4CRITICAL

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
6 February 2025

What is CVE-2023-5878?

The Honeywell OneWireless Wireless Device Manager contains a vulnerability that allows authenticated users to execute arbitrary commands through a compromised firmware update process. This vulnerability could be exploited by attackers to perform unauthorized actions on the system. Honeywell advises users to upgrade to version R322.3, R330.2, or the latest version available to mitigate the risk associated with this issue.

Affected Version(s)

OneWireless Network Wireless Device Manager Linux 310.1 <= 322.2

OneWireless Network Wireless Device Manager Linux 323.1 <= 330.1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-5878 : Command Injection Flaw in Honeywell OneWireless Wireless Device Manager