Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product.
Metrics
Affected Vendors & Products
References
History
Wed, 07 May 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Honeywell
Honeywell mb-secure Honeywell mb-secure Firmware Honeywell mb-secure Pro Honeywell mb-secure Pro Firmware |
|
CPEs | cpe:2.3:h:honeywell:mb-secure:-:*:*:*:*:*:*:* cpe:2.3:h:honeywell:mb-secure_pro:-:*:*:*:*:*:*:* cpe:2.3:o:honeywell:mb-secure_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:honeywell:mb-secure_pro_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Honeywell
Honeywell mb-secure Honeywell mb-secure Firmware Honeywell mb-secure Pro Honeywell mb-secure Pro Firmware |
Fri, 02 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 02 May 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product. | |
Title | Authenticated command injection | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Honeywell
Published: 2025-05-02T12:39:39.979Z
Updated: 2025-05-02T13:32:33.807Z
Reserved: 2025-03-21T13:18:29.509Z
Link: CVE-2025-2605

Updated: 2025-05-02T13:32:23.944Z

Status : Analyzed
Published: 2025-05-02T13:15:46.440
Modified: 2025-05-07T16:52:39.650
Link: CVE-2025-2605

No data.