Malformed Message Could Lead to Remote Code Execution
CVE-2023-5396

7.4HIGH

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
17 April 2024

What is CVE-2023-5396?

A vulnerability exists in specific Honeywell products where the server's handling of a malformed message can lead to a stack overflow. This issue allows an attacker to create a connection for an arbitrary hostname, potentially leading to remote code execution. For specific mitigations and guidance, refer to the Honeywell Security Notification, which recommends updating to secure versions.

Affected Version(s)

Experion Server Experion LX 520.2 <= 520.2 TCU4

Experion Server Experion LX 511.1 <= 511.5 TCU4 HF3

Experion Server Experion LX 520.1 <= 520.1 TCU4

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-5396 : Malformed Message Could Lead to Remote Code Execution