Controller DOS on sending error response
CVE-2023-26597

7.5HIGH

Key Information:

Vendor

Honeywell

Status
Vendor
CVE Published:
13 July 2023

What is CVE-2023-26597?

A buffer overflow vulnerability exists in Honeywell controllers, allowing a specially crafted message to cause denial of service (DoS) conditions. This vulnerability enables an attacker to manipulate the controller's message handling process, potentially disrupting service and impacting overall system operations. It is crucial for users to refer to Honeywell's security advisories for recommendations on upgrading and version management to mitigate this risk.

Affected Version(s)

C300 Experion LX 510.1 <= 511.5TCU3

C300 Experion LX 520.1 <= 520.1TCU4

C300 Experion LX 520.2 <= 520.2TCU2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.