Honeywell Security Notification: Malformed Messages Could Lead to Remote Code Execution or Failure
CVE-2023-5397

8.1HIGH

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
17 April 2024

What is CVE-2023-5397?

A security vulnerability has been identified within certain Honeywell products, where the server may process a malformed message intended for establishing a new connection. This flaw can allow an attacker to execute arbitrary code remotely or induce a failure in the affected system. It is crucial for users to follow the guidance provided in the Honeywell Security Notification regarding recommended upgrades and version compatibility to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Experion Server Experion LX 520.2 <= 520.2 TCU4

Experion Server Experion LX 511.1 <= 511.5 TCU4 HF3

Experion Server Experion LX 520.1 <= 520.1 TCU4

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.