CVE-2022-4240 MEDIUM

CVE-2022-4240: Unauthenticated API allowing an attacker to obtain the information about network resources

Vendor Honeywell
Product OneWireless
Weakness CWE-306 · Missing auth
Published May 30, 2023
Last update January 9, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1

Key dates

02Disclosure timeline

May 30, 2023 CVE published
January 9, 2025 Record updated