PT-2024-1736 · Honeywell · Honeywell Experion Controledge Virtualuoc+1

Published

2024-01-30

·

Updated

2024-07-09

·

CVE-2023-5390

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC (affected versions not specified)
Description The issue is related to incorrect restriction of directory path names with limited access, potentially allowing an attacker to read files from the controller, exposing limited information from the device. An attacker could exploit this to read files from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC.
Recommendations Update to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. As a temporary workaround, consider restricting access to sensitive files and directories on the controller until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-01444
CVE-2023-5390

Affected Products

Controledge Uoc
Honeywell Experion Controledge Virtualuoc