Directory Traversal Vulnerability in Honeywell Experion PKS Products
CVE-2014-5436

7.5HIGH

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
8 April 2019

What is CVE-2014-5436?

A directory traversal vulnerability found in the confd.exe module of Honeywell's Experion PKS can potentially lead to unauthorized access to sensitive information. This issue affects multiple versions of the software, specifically those prior to R400.6, R410.6, and R430.2. Honeywell urges all users operating outdated versions to upgrade to a supported version to mitigate the risk and enhance their security posture.

Affected Version(s)

Experion PKS R40x before R400.6

Experion PKS R41x before R410.6

Experion PKS R43x before R430.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.