CVE-2022-43485
Insecure random number used for generating keys for signing Jwt tokens
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
Produtos afetados
Honeywell · OneWirelessQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://process.honeywell.com/