Insufficient Data Authenticity in Honeywell Experion PKS Safety Manager
CVE-2022-30316
What is CVE-2022-30316?
The Honeywell Experion PKS Safety Manager version 5.02 is affected by a vulnerability related to insufficient data authenticity verification during firmware updates. It has been found that the firmware update process lacks robust authentication mechanisms, as firmware images are unsigned and rely solely on insecure checksum methods for integrity verification. This raises significant concerns as attackers with access to the serial interface can exploit hardcoded credentials to manipulate firmware. The vulnerability enables potential unauthorized firmware updates, allowing for remote code execution and denial of service. While a reboot is necessary to initiate a firmware update, which presents a barrier to exploitation, sophisticated attackers may still find ways to trigger this action or exploit other vulnerabilities.