File Disclosure Vulnerability in Honeywell ControlEdge Products
CVE-2023-5390

5.3MEDIUM

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
31 January 2024

What is CVE-2023-5390?

This vulnerability allows attackers to potentially exploit the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC, enabling them to read sensitive files from the controller. This exposure of information can lead to security risks for industrial control systems. Honeywell urges users to upgrade to the latest product versions to mitigate this risk effectively. For detailed guidance on upgrading and version management, consult the Honeywell Security Notification.

Affected Version(s)

ControlEdge UOC Experion LX 520.2 <= 520.2 TCU4

ControlEdge UOC Experion LX 511.1 <= 511.5 TCU4 HF3

ControlEdge UOC Experion LX 520.1 <= 520.1 TCU4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.