CVE-2025-2605

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:honeywell:mb-secure_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:mb-secure:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:honeywell:mb-secure_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:mb-secure_pro:-:*:*:*:*:*:*:*

History

17 May 2025, 06:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/May/19 -

07 May 2025, 16:52

Type Values Removed Values Added
CPE cpe:2.3:h:honeywell:mb-secure_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:mb-secure_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:mb-secure_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:mb-secure:-:*:*:*:*:*:*:*
First Time Honeywell mb-secure
Honeywell mb-secure Pro
Honeywell mb-secure Pro Firmware
Honeywell mb-secure Firmware
Honeywell
References () https://www.honeywell.com/us/en/product-security#security-notices - () https://www.honeywell.com/us/en/product-security#security-notices - Vendor Advisory
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('Inyección de comandos del sistema operativo') en Honeywell MB-Secure permite el abuso de privilegios. Este problema afecta a MB-Secure desde la versión 11.04 hasta la 12.53 y a MB-Secure PRO desde la versión 01.06 hasta la 03.09. Honeywell también recomienda actualizar a la versión más reciente de este producto.

02 May 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-02 13:15

Updated : 2025-05-17 06:15


NVD link : CVE-2025-2605

Mitre link : CVE-2025-2605

CVE.ORG link : CVE-2025-2605


JSON object : View

Products Affected

honeywell

  • mb-secure_pro_firmware
  • mb-secure_pro
  • mb-secure
  • mb-secure_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')