CVE-2023-22435: Server bad parsing implementation - stack overflow in server::get_db_path_for_driver
Published Jul 13, 2023
·Updated
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
Affected Software
16 affected components
Honeywell Experion server>=501.1<=501.6hf8
Honeywell Experion server>=510.1<=510.2hf12
Honeywell Experion server>=511.1<=511.5tcu3
Honeywell Experion server>=520.1<=520.1tcu4
Honeywell Experion server>=520.2<=520.2tcu2
Honeywell Experion Station>=501.1<=501.6hf8
Honeywell Experion Station>=510.1<=510.2hf12
Honeywell Experion Station>=511.1<=511.5tcu3
Honeywell Experion Station>=520.1<=520.1tcu4
Honeywell Experion Station>=520.2<=520.2tcu2
Honeywell Engineering Station>=510.1<=511.5tcu3
Honeywell Engineering Station>=520.1<=520.1tcu4
Honeywell Engineering Station>=520.2<=520.2tcu2
Honeywell Direct Station>=510.1<=511.5tcu3
Honeywell Direct Station>=520.1<=520.1tcu4
Honeywell Direct Station>=520.2<=520.2tcu2
Event History
Jul 13, 2023
CVE Published
via MITRE·10:53 AM
Data Sourced
via MITRE·10:53 AM
DescriptionSeverityWeakness
Data Sourced
11:15 AM
Description
Frequently Asked Questions
1
What is CVE-2023-22435?
CVE-2023-22435 is a vulnerability that can cause a denial-of-service (DoS) attack on the Experion server by exploiting a stack overflow.
2
Which software is affected by CVE-2023-22435?
The Honeywell Experion Server, Experion Station, Engineering Station, and Direct Station are affected by CVE-2023-22435.
3
What is the severity of CVE-2023-22435?
CVE-2023-22435 has a severity rating of 7.5 (high).
4
How can CVE-2023-22435 be exploited?
CVE-2023-22435 can be exploited by sending a specially crafted message to the Experion server, causing a stack overflow and resulting in a DoS condition.
5
How can I mitigate the CVE-2023-22435 vulnerability?
To mitigate the CVE-2023-22435 vulnerability, it is recommended to apply the necessary patches and updates provided by Honeywell.