Honeywell International Inc.
Self-Reporting Analysis
Of all the CVEs published by Honeywell International Inc. as a CNA, 37.9% affect products that Honeywell International Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Honeywell International Inc., 21.4% are self-published by Honeywell International Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Honeywell International Inc. over time
Top CVEs
All CVEs published by Honeywell International Inc. as a CNA, regardless of affected vendor or product.
58 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3710CRITICAL Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004 | Sep 12, 2023 | 9.8 | 68 | NO | YES |
CVE-2025-2605HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure | May 2, 2025 | 8.8 | 33 | NO | NO |
CVE-2023-3243CRITICAL
** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash
and utilize it to create new sessions. The hash is also a poorly salted MD5
hash, which could resul | Jun 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-4272HIGH Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x10 | Apr 5, 2026 | 8.1 | 29 | NO | NO |
CVE-2025-2523CRITICAL The Honeywell Experion PKS
and OneWireless WDM
contains an Integer Underflow
vulnerability
in the component Control Data Access (CDA). An attacker could potentially exploi | Jul 10, 2025 | 9.4 | 29 | NO | NO |
CVE-2025-3938CRITICAL Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This | May 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-3936CRITICAL Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Exploiting Incorr | May 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2026-13742MEDIUM Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability. An attacker could potentially exploit th | Jun 29, 2026 | 5.9 | 28 | NO | NO |
CVE-2026-11804MEDIUM Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux | Jul 23, 2026 | 5.2 | 27 | NO | NO |
CVE-2025-3945CRITICAL Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX all | May 22, 2025 | 9.8 | 27 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (58 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Honeywell International Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Honeywell International Inc. as a CNA — matched by CVE ID, not by organization name.