Server Information Leak Due to Error Handling Vulnerability
CVE-2023-5405

5.9MEDIUM

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
17 April 2024

What is CVE-2023-5405?

A vulnerability exists in the CDA Server where an error triggered by a specially crafted message can lead to the leakage of sensitive server information from the process memory. This issue can allow unauthorized parties to access confidential data, posing significant risks to security and privacy. It is advisable to review Honeywell's security advisory for effective mitigation steps, including recommended upgrades and version management.

Affected Version(s)

Experion Server Experion LX 520.2 <= 520.2 TCU4

Experion Server Experion LX 511.1 <= 511.5 TCU4 HF3

Experion Server Experion LX 520.1 <= 520.1 TCU4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.