Honeywell Product Update: Addressing Malformed Message Vulnerability
CVE-2023-5393

7.4HIGH

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
11 April 2024

What is CVE-2023-5393?

A vulnerability exists in Honeywell Security Solutions where a server may experience a stack overflow due to the processing of a malformed message directed at a hostname. This issue could potentially lead to remote code execution, allowing an attacker to execute arbitrary code on the affected system. Users are strongly advised to update their products to the latest versions as recommended in Honeywell Security Notification to mitigate this risk.

Affected Version(s)

Experion Server Experion LX 520.2

Experion Server Experion LX 511.1

Experion Server Experion LX 520.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-5393 : Honeywell Product Update: Addressing Malformed Message Vulnerability