Vulnerabilities > Honeywell > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-13 CVE-2023-25078 Out-of-bounds Write vulnerability in Honeywell products
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.
network
low complexity
honeywell CWE-787
7.5
2023-07-13 CVE-2023-25770 Deserialization of Untrusted Data vulnerability in Honeywell C300 Firmware
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
network
low complexity
honeywell CWE-502
7.5
2023-05-30 CVE-2022-4240 Missing Authentication for Critical Function vulnerability in Honeywell Onewireless Network Wireless Device Manager Firmware R322.1
Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1
network
low complexity
honeywell CWE-306
7.5
2022-10-28 CVE-2021-38399 Path Traversal vulnerability in Honeywell products
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.
network
low complexity
honeywell CWE-22
7.5
2022-09-16 CVE-2022-2332 Incorrect Permission Assignment for Critical Resource vulnerability in Honeywell Softmaster 4.51
A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment.
local
low complexity
honeywell CWE-732
7.8
2022-09-16 CVE-2022-2333 Uncontrolled Search Path Element vulnerability in Honeywell Softmaster 4.51
If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster version 4.51 application’s context and permissions.
local
low complexity
honeywell CWE-427
7.8
2022-07-28 CVE-2022-30313 Missing Authentication for Critical Function vulnerability in Honeywell Safety Manager Firmware
Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function.
network
low complexity
honeywell CWE-306
7.5
2022-07-28 CVE-2022-30319 Authentication Bypass by Spoofing vulnerability in Honeywell Saia PG5 Controls Suite
Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass.
low complexity
honeywell CWE-290
8.1
2022-07-15 CVE-2022-30243 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Honeywell Alterton Visual Logic Firmware
Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users.
network
low complexity
honeywell CWE-829
8.8
2022-07-15 CVE-2022-30244 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Honeywell Alerton Ascent Control Module Firmware
Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming writes from remote users.
network
low complexity
honeywell CWE-829
8.0