Controller stack overflow when decoding messages from the server
CVE-2023-24480
9.8CRITICAL
What is CVE-2023-24480?
This vulnerability allows an attacker to potentially cause a Denial of Service (DoS) condition in affected Honeywell Controller products. The issue stems from a stack overflow that occurs when decoding messages from the server, which can prevent proper functioning of the device. To mitigate risks, users should refer to Honeywell's security notifications for recommended upgrades and versioning information.
Affected Version(s)
C300 Experion LX 510.1 <= 511.5TCU3
C300 Experion LX 520.1 <= 520.1TCU4
C300 Experion LX 520.2 <= 520.2TCU2
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
