Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data  including customer data, security system status, and event history.
History

Wed, 25 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Description Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data  including customer data, security system status, and event history. Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data  including customer data, security system status, and event history.

Wed, 18 Feb 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Honeywell
Honeywell masmobile Asp.net Services
Honeywell masmobile Classic
CPEs cpe:2.3:a:honeywell:masmobile_asp.net_services:*:*:*:*:*:*:*:*
cpe:2.3:a:honeywell:masmobile_classic:*:*:*:*:*:android:*:*
cpe:2.3:a:honeywell:masmobile_classic:*:*:*:*:*:iphone_os:*:*
Vendors & Products Honeywell
Honeywell masmobile Asp.net Services
Honeywell masmobile Classic

cve-icon MITRE

Status: PUBLISHED

Assigner: Carrier

Published:

Updated: 2024-08-28T16:23:17.832Z

Reserved: 2023-06-22T00:00:00.000Z

Link: CVE-2023-36483

cve-icon Vulnrichment

Updated: 2024-08-02T16:45:57.162Z

cve-icon NVD

Status : Modified

Published: 2024-03-16T05:15:18.577

Modified: 2026-02-25T17:22:36.310

Link: CVE-2023-36483

cve-icon Redhat

No data.