CVE-2023-36483: Honeywell Masmobile ASP.NET Services

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data  including customer data, security system status, and event history.

Affected products

  • Honeywell Masmobile ASP.NET Services: up to and including 1.9
  • Honeywell Masmobile Classic: up to and including 1.7.24; up to and including 1.16.18

Published 2024-03-16. Last modified 2026-06-17.