Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product.
References
Link | Resource |
---|---|
https://www.honeywell.com/us/en/product-security#security-notices | Vendor Advisory |
http://seclists.org/fulldisclosure/2025/May/19 |
Configurations
History
17 May 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 May 2025, 16:52
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:honeywell:mb-secure_pro:-:*:*:*:*:*:*:* cpe:2.3:o:honeywell:mb-secure_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:honeywell:mb-secure_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:honeywell:mb-secure:-:*:*:*:*:*:*:* |
|
First Time |
Honeywell mb-secure
Honeywell mb-secure Pro Honeywell mb-secure Pro Firmware Honeywell mb-secure Firmware Honeywell |
|
References | () https://www.honeywell.com/us/en/product-security#security-notices - Vendor Advisory | |
Summary |
|
02 May 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-02 13:15
Updated : 2025-05-17 06:15
NVD link : CVE-2025-2605
Mitre link : CVE-2025-2605
CVE.ORG link : CVE-2025-2605
JSON object : View
Products Affected
honeywell
- mb-secure_pro_firmware
- mb-secure_pro
- mb-secure
- mb-secure_firmware
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')