VulnerabilityModified
CVE-2022-43485
This vulnerability may allow attacker to manipulate claims in client's JWT token.
MEDIUM 6.5EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.47% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- honeywell/onewireless network wireless device manager firmware
- Source
- psirt@honeywell.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.