Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data  including customer data, security system status, and event history.
History

Wed, 18 Feb 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Honeywell
Honeywell masmobile Asp.net Services
Honeywell masmobile Classic
CPEs cpe:2.3:a:honeywell:masmobile_asp.net_services:*:*:*:*:*:*:*:*
cpe:2.3:a:honeywell:masmobile_classic:*:*:*:*:*:android:*:*
cpe:2.3:a:honeywell:masmobile_classic:*:*:*:*:*:iphone_os:*:*
Vendors & Products Honeywell
Honeywell masmobile Asp.net Services
Honeywell masmobile Classic

cve-icon MITRE

Status: PUBLISHED

Assigner: Carrier

Published:

Updated: 2024-08-28T16:23:17.832Z

Reserved: 2023-06-22T00:00:00

Link: CVE-2023-36483

cve-icon Vulnrichment

Updated: 2024-08-02T16:45:57.162Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-16T05:15:18.577

Modified: 2026-02-18T14:26:08.403

Link: CVE-2023-36483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.