Controller stack overflow when decoding messages from the server
CVE-2023-24480

9.8CRITICAL

Key Information:

Vendor

Honeywell

Status
Vendor
CVE Published:
13 July 2023

What is CVE-2023-24480?

This vulnerability allows an attacker to potentially cause a Denial of Service (DoS) condition in affected Honeywell Controller products. The issue stems from a stack overflow that occurs when decoding messages from the server, which can prevent proper functioning of the device. To mitigate risks, users should refer to Honeywell's security notifications for recommended upgrades and versioning information.

Affected Version(s)

C300 Experion LX 510.1 <= 511.5TCU3

C300 Experion LX 520.1 <= 520.1TCU4

C300 Experion LX 520.2 <= 520.2TCU2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.