CVE-2023-23585: Server DoS due to heap overflow
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23585?
CVE-2023-23585 is a vulnerability that allows for a denial of service (DoS) attack on Honeywell Experion Server and Experion Station software.
How does CVE-2023-23585 work?
CVE-2023-23585 works by exploiting a heap overflow vulnerability in the handling of a specially crafted message during a specific configuration operation.
How severe is CVE-2023-23585?
CVE-2023-23585 has a severity rating of 7.5 out of 10, which is considered critical.
Which versions of Honeywell Experion Server and Experion Station are affected by CVE-2023-23585?
Versions between 501.1 and 501.6hf8, 510.1 and 510.2hf12, 511.1 and 511.5tcu3, and 520.1 and 520.2tcu2 of Honeywell Experion Server and Experion Station are affected by CVE-2023-23585.
How can I fix CVE-2023-23585?
To fix CVE-2023-23585, it is recommended to upgrade to a version of Honeywell Experion Server and Experion Station that is not affected by the vulnerability.