File Modification Vulnerability in Honeywell Experion ControlEdge Products
CVE-2023-5389

9.1CRITICAL

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
30 January 2024

What is CVE-2023-5389?

A significant file modification vulnerability exists within Honeywell's Experion ControlEdge VirtualUOC and ControlEdge UOC products. This flaw could allow an attacker to manipulate files, which may lead to unexpected system behaviors due to configuration changes or updates to essential files. Such manipulation can pave the way for the execution of malicious applications if certain conditions are met. Honeywell advises all users to ensure they are running the latest versions of their products as a security precaution. For more information about security updates and versioning, refer to the Honeywell Security Notification.

Affected Version(s)

ControlEdge UOC Experion LX 520.2 <= 520.2 TCU4

ControlEdge UOC Experion LX 511.1 <= 511.5 TCU4 HF3

ControlEdge UOC Experion LX 520.1 <= 520.1 TCU4

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.