PT-2025-29163 · Honeywell · Honeywell Experion Pks

Positive Technologies

·

Published

2025-04-25

·

Updated

2025-07-11

·

CVE-2025-3947

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions: Honeywell Experion PKS versions 520.1 through 520.2 TCU9 Honeywell Experion PKS versions 530 through 530 TCU3
Description: The Honeywell Experion PKS contains an integer underflow vulnerability in the Control Data Access (CDA) component. An attacker could exploit this vulnerability, leading to input data manipulation. This could result in improper integer data value checking during subtraction, potentially leading to a denial of service.
Recommendations: Honeywell Experion PKS versions 520.1 through 520.2 TCU9: Update to version 520.2 TCU9 HF1. Honeywell Experion PKS versions 530 through 530 TCU3: Update to version 530.1 TCU3 HF1.

Fix

Integer Underflow

Weakness Enumeration

Related Identifiers

BDU:2025-06924
CVE-2025-3947

Affected Products

Honeywell Experion Pks