PT-2025-29163 · Honeywell · Honeywell Experion Pks
Positive Technologies
·
Published
2025-04-25
·
Updated
2025-07-11
·
CVE-2025-3947
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions:
Honeywell Experion PKS versions 520.1 through 520.2 TCU9
Honeywell Experion PKS versions 530 through 530 TCU3
Description:
The Honeywell Experion PKS contains an integer underflow vulnerability in the Control Data Access (CDA) component. An attacker could exploit this vulnerability, leading to input data manipulation. This could result in improper integer data value checking during subtraction, potentially leading to a denial of service.
Recommendations:
Honeywell Experion PKS versions 520.1 through 520.2 TCU9: Update to version 520.2 TCU9 HF1.
Honeywell Experion PKS versions 530 through 530 TCU3: Update to version 530.1 TCU3 HF1.
Fix
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Honeywell Experion Pks