← Back to home
ICSA-23-075-06  ·  Published 2023-04-03  ·  View on CISA ICS-CERT ↗

Honeywell OneWireless Wireless Device Manager

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could disclose sensitive information, allow privilege escalation, or allow remote code execution.

Remediations

  • Honeywell recommends users upgrade OneWireless WDM to release R322.2. Download information includes the following: Product: OneWireless. Version: 322.2
  • For instructions on this process: Go to the Honeywell Website and sign in. Select “Support” at the top of the web page. Select “Product Documents & Downloads.” In the given search box, search for: “OneWireless R322.2” or, after logging in, select the hyperlink: “OneWireless R322.2.”
  • Honeywell advises users to ensure OneWireless security best practices are followed on the network to which the OneWireless WDM is attached to ensure access is limited to authorized users only. Users should ensure the backup files are maintained in a network location or physical drive with access limited to authorized users only and should not share them.
  • The recommended network installation guidelines are available in the Honeywell guide, "Network-Planning-and-Installation-Guide-OWDOC-X253-en-322." For access, users should visit the Honeywell Website and sign in, select “Support” at the top of the web page, then select “Product Documents & Downloads.” In the given search box, search for: “Network-Planning-and-Installation-Guide-OWDOC-X253-en-322” or, after logging in, select the hyperlink: Network-Planning-and-Installation-Guide-OWDOC-X253-en-322.

Affected Vendors

Honeywell

Affected Products (1)

Honeywell · OneWireless WDM <=R322.1

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more