Command Injection Flaw in Honeywell OneWireless Wireless Device Manager
CVE-2023-5878
9.4CRITICAL
What is CVE-2023-5878?
The Honeywell OneWireless Wireless Device Manager contains a vulnerability that allows authenticated users to execute arbitrary commands through a compromised firmware update process. This vulnerability could be exploited by attackers to perform unauthorized actions on the system. Honeywell advises users to upgrade to version R322.3, R330.2, or the latest version available to mitigate the risk associated with this issue.
Affected Version(s)
OneWireless Network Wireless Device Manager Linux 310.1 <= 322.2
OneWireless Network Wireless Device Manager Linux 323.1 <= 330.1
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
