PT-2023-3881 · Honeywell · Honeywell Experion Pks+2
Published
2023-07-13
·
Updated
2024-04-22
·
CVE-2023-26597
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Honeywell Experion PKS versions (affected versions not specified)
Honeywell Experion LX versions (affected versions not specified)
Honeywell Experion PlantCruise versions (affected versions not specified)
Description
The issue is related to a buffer overflow in the handling of a specially crafted message received by the controller, which can cause a denial of service (DoS). The vulnerability is also associated with incorrect clearing or release of resources in the software of programmable logic controllers. An attacker can exploit this vulnerability remotely, leading to a denial of service.
Recommendations
For Honeywell Experion PKS, refer to Honeywell Security Notification for recommendations on upgrading and versioning.
For Honeywell Experion LX, refer to Honeywell Security Notification for recommendations on upgrading and versioning.
For Honeywell Experion PlantCruise, refer to Honeywell Security Notification for recommendations on upgrading and versioning.
As a temporary workaround, consider disabling the handling of specially crafted messages until a patch is available. Restrict access to the vulnerable controller to minimize the risk of exploitation.
Fix
Resource Exhaustion
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Honeywell Experion Lx
Honeywell Experion Pks
Honeywell Experion Plantcruise