File Inclusion Vulnerability in Honeywell Experion PKS by Honeywell
CVE-2014-9186

9.8CRITICAL

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
8 April 2019

What is CVE-2014-9186?

A file inclusion vulnerability exists in the confd.exe module of Honeywell Experion PKS, affecting specific versions prior to R400.6, R410.6, and R430.2. This flaw allows the potential for unauthorized acceptance of arbitrary files, which may lead to information disclosure and remote code execution risks. Honeywell advises users running outdated versions to upgrade to supported releases to mitigate these security concerns.

Affected Version(s)

Experion PKS R40x before R400.6

Experion PKS R41x before R410.6

Experion PKS R43x before R430.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.