Honeywell Security Notification: Stack Overflow Vulnerability Affects Remote Code Execution
CVE-2023-5401

8.1HIGH

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
17 April 2024

What is CVE-2023-5401?

A stack overflow vulnerability exists in specific Honeywell products due to the improper handling of malformed messages. This flaw could allow an attacker to execute arbitrary code remotely or cause the affected system to fail. Users are strongly advised to upgrade to the latest versions as outlined in the Honeywell Security Notification.

Affected Version(s)

Experion Server Experion LX 520.2 <= 520.2 TCU4

Experion Server Experion LX 511.1 <= 511.5 TCU4 HF3

Experion Server Experion LX 520.1 <= 520.1 TCU4

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.