PT-2023-3882 · Honeywell · Honeywell Experion Pks+2
Published
2023-07-13
·
Updated
2024-04-22
·
CVE-2023-25948
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Honeywell Experion PKS (affected versions not specified)
Honeywell Experion LX (affected versions not specified)
Experion PlantCruise (affected versions not specified)
Description
The issue is related to a server information leak of configuration data when an error is generated in response to a specially crafted message. This is due to insufficient validation of return values in the software of Honeywell Experion PKS, Experion LX, and Experion PlantCruise programmable logic controllers and distributed control systems. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations
For Honeywell Experion PKS, consider upgrading to a version that addresses the issue, following recommendations from Honeywell Security Notification.
For Honeywell Experion LX, consider upgrading to a version that addresses the issue, following recommendations from Honeywell Security Notification.
For Experion PlantCruise, consider upgrading to a version that addresses the issue, following recommendations from Honeywell Security Notification.
As a temporary workaround, consider restricting access to error messages and configuration data to minimize the risk of exploitation.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Experion Plantcruise
Honeywell Experion Lx
Honeywell Experion Pks