CVE-2023-36483: Honeywell Masmobile ASP.NET Services
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history.
Affected products
- Honeywell Masmobile ASP.NET Services: up to and including 1.9
- Honeywell Masmobile Classic: up to and including 1.7.24; up to and including 1.16.18
Published 2024-03-16. Last modified 2026-06-17.