PT-2023-3878 · Honeywell · Honeywell Experion Pks+2
Published
2023-07-13
·
Updated
2024-04-22
·
CVE-2023-25178
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Honeywell Experion PKS (affected versions not specified)
Honeywell Experion LX (affected versions not specified)
Experion PlantCruise (affected versions not specified)
Description
The issue is related to insufficient data authentication in the software of Honeywell Experion PKS, Experion LX, and Experion PlantCruise. This could allow a remote attacker to gain unauthorized access to protected information. The vulnerability may also enable remote code execution if the controller is loaded with malicious firmware.
Recommendations
For Honeywell Experion PKS, refer to the Honeywell Security Notification for recommendations on upgrading and versioning.
For Honeywell Experion LX, refer to the Honeywell Security Notification for recommendations on upgrading and versioning.
For Experion PlantCruise, refer to the Honeywell Security Notification for recommendations on upgrading and versioning.
As a temporary workaround, consider restricting access to the controllers to minimize the risk of exploitation.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Experion Plantcruise
Honeywell Experion Lx
Honeywell Experion Pks