PT-2023-3878 · Honeywell · Honeywell Experion Pks+2

Published

2023-07-13

·

Updated

2024-04-22

·

CVE-2023-25178

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Honeywell Experion PKS (affected versions not specified) Honeywell Experion LX (affected versions not specified) Experion PlantCruise (affected versions not specified)
Description The issue is related to insufficient data authentication in the software of Honeywell Experion PKS, Experion LX, and Experion PlantCruise. This could allow a remote attacker to gain unauthorized access to protected information. The vulnerability may also enable remote code execution if the controller is loaded with malicious firmware.
Recommendations For Honeywell Experion PKS, refer to the Honeywell Security Notification for recommendations on upgrading and versioning. For Honeywell Experion LX, refer to the Honeywell Security Notification for recommendations on upgrading and versioning. For Experion PlantCruise, refer to the Honeywell Security Notification for recommendations on upgrading and versioning. As a temporary workaround, consider restricting access to the controllers to minimize the risk of exploitation.

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

BDU:2023-04170
CVE-2023-25178

Affected Products

Experion Plantcruise
Honeywell Experion Lx
Honeywell Experion Pks