{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T03:03:23.545","vulnerabilities":[{"cve":{"id":"CVE-2025-2605","sourceIdentifier":"psirt@honeywell.com","published":"2025-05-02T13:15:46.440","lastModified":"2026-06-17T09:07:16.293","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product."},{"lang":"es","value":"La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('Inyección de comandos del sistema operativo') en Honeywell MB-Secure permite el abuso de privilegios. Este problema afecta a MB-Secure desde la versión 11.04 hasta la 12.53 y a MB-Secure PRO desde la versión 01.06 hasta la 03.09. Honeywell también recomienda actualizar a la versión más reciente de este producto."}],"affected":[{"source":"psirt@honeywell.com","affectedData":[{"vendor":"Honeywell","product":"MB-Secure","defaultStatus":"affected","versions":[{"version":"V11.04","lessThan":"V12.53","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@honeywell.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-02T13:32:21.228869Z","id":"CVE-2025-2605","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@honeywell.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:honeywell:mb-secure_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"11.04","versionEndExcluding":"12.53","matchCriteriaId":"9A3948BD-0AA0-4F44-87DE-6F93FE58A3CC"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:honeywell:mb-secure:-:*:*:*:*:*:*:*","matchCriteriaId":"068F05DB-54F1-4F6B-8A1B-501E7841469B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:honeywell:mb-secure_pro_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"01.06","versionEndExcluding":"03.09","matchCriteriaId":"D6782306-FD38-4001-9F99-9B1A9EC820F9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:honeywell:mb-secure_pro:-:*:*:*:*:*:*:*","matchCriteriaId":"F8F28351-A605-4F24-B62B-408D77C661E7"}]}]}],"references":[{"url":"https://www.honeywell.com/us/en/product-security#security-notices","source":"psirt@honeywell.com","tags":["Vendor Advisory"]},{"url":"http://seclists.org/fulldisclosure/2025/May/19","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}