CVE-2022-43485

Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerabilitymay allow attacker to manipulate claims in client's JWT token.This issue affects OneWireless version 322.1
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.2 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
HoneywellCNA
6.2 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
VendorProductVersion
honeywellonewireless_network_wireless_device_manager_firmware
𝑥
< r322.2
𝑥
= Vulnerable software versions