PT-2022-3079 · Honeywell · Honeywell Experion Lx

Daniel Dos Santos

+1

·

Published

2022-06-22

·

Updated

2024-02-13

·

CVE-2022-30317

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Honeywell Experion LX through 2022-05-06
Description The issue concerns a missing authentication feature in the Honeywell Experion LX Control Data Access (CDA) EpicMo protocol, which is used for device diagnostics and maintenance purposes. This protocol, characterized as Honeywell Control Data Access (CDA) EpicMo (55565/TCP), lacks authentication functionality, allowing any attacker capable of communicating with the ports in question to invoke desired functionality. The potential impact includes firmware manipulation and denial of service, as an attacker could issue firmware download commands or reboot devices.
Recommendations For Honeywell Experion LX through 2022-05-06, consider disabling the EpicMo protocol (55565/TCP) until a patch or fix is available to mitigate the risk of firmware manipulation and denial of service. Restrict access to the Control Data Access (CDA) EpicMo protocol to minimize the risk of exploitation. Avoid using the protocol for device diagnostics and maintenance purposes until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2022-03749
CVE-2022-30317

Affected Products

Honeywell Experion Lx