Remote Code Execution through Server Communication
CVE-2023-5406

5.9MEDIUM

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
17 April 2024

What is CVE-2023-5406?

A vulnerability exists in Honeywell Controllers that could allow an attacker to execute arbitrary code remotely. This security issue arises from improper handling of messages between the server and the controller, potentially leading to unauthorized access and control. Affected users are urged to consult the Honeywell Security Notification for critical upgrade paths and version recommendations to mitigate this risk.

Affected Version(s)

Experion Server Experion LX 520.2 <= 520.2 TCU4

Experion Server Experion LX 511.1 <= 511.5 TCU4 HF3

Experion Server Experion LX 520.1 <= 520.1 TCU4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-5406 : Remote Code Execution through Server Communication