Vulnerabilities > Honeywell > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-13 | CVE-2023-25078 | Out-of-bounds Write vulnerability in Honeywell products Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning. | 7.5 |
2023-07-13 | CVE-2023-25770 | Deserialization of Untrusted Data vulnerability in Honeywell C300 Firmware Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning. | 7.5 |
2023-05-30 | CVE-2022-4240 | Missing Authentication for Critical Function vulnerability in Honeywell Onewireless Network Wireless Device Manager Firmware R322.1 Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1 | 7.5 |
2022-10-28 | CVE-2021-38399 | Path Traversal vulnerability in Honeywell products Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories. | 7.5 |
2022-09-16 | CVE-2022-2332 | Incorrect Permission Assignment for Critical Resource vulnerability in Honeywell Softmaster 4.51 A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment. | 7.8 |
2022-09-16 | CVE-2022-2333 | Uncontrolled Search Path Element vulnerability in Honeywell Softmaster 4.51 If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster version 4.51 application’s context and permissions. | 7.8 |
2022-07-28 | CVE-2022-30313 | Missing Authentication for Critical Function vulnerability in Honeywell Safety Manager Firmware Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. | 7.5 |
2022-07-28 | CVE-2022-30319 | Authentication Bypass by Spoofing vulnerability in Honeywell Saia PG5 Controls Suite Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. | 8.1 |
2022-07-15 | CVE-2022-30243 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Honeywell Alterton Visual Logic Firmware Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. | 8.8 |
2022-07-15 | CVE-2022-30244 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Honeywell Alerton Ascent Control Module Firmware Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming writes from remote users. | 8.0 |