Honeywell Warns of Remote Code Execution Vulnerability in Product
CVE-2023-5394

7.4HIGH

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
11 April 2024

What is CVE-2023-5394?

A vulnerability exists in Honeywell GCL products where the server can be affected by a malformed GCL message that contains an excessively large hostname. This can lead to a stack overflow, potentially enabling remote code execution. It is recommended that users upgrade to the latest version of the product to mitigate this issue. Honeywell provides guidance through their Security Notification for necessary updates and versioning information.

Affected Version(s)

Experion Server Experion LX 520.2 <= 520.2 TCU4

Experion Server Experion LX 511.1 <= 511.5 TCU4 HF3

Experion Server Experion LX 520.1 <= 520.1 TCU4

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.