漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OneWireless command injection possible when updating firmware
Vulnerability Description
Honeywell OneWireless
Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to
R322.3, R330.2 or the most recent version of this product2.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
Honeywell OneWireless Wireless Device Manager 安全漏洞
Vulnerability Description
Honeywell OneWireless Wireless Device Manager(Honeywell OneWireless WDM)是美国霍尼韦尔(Honeywell)公司的一个无线设备管理器。 Honeywell OneWireless Wireless Device Manager存在安全漏洞。攻击者利用该漏洞可以注入命令。以下版本受到影响:R310.x版本、R320.x版本、R321.x版本、R322.1版本、R322.2版本、R323.x版本和R330.1版本。
CVSS Information
N/A
Vulnerability Type
N/A