First published: Thu Jul 13 2023(Updated: )
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.
Credit: psirt@honeywell.com psirt@honeywell.com
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Experion Server | >=501.1<=501.6hf8 | |
Honeywell Experion Server | >=510.1<=510.2hf12 | |
Honeywell Experion Server | >=511.1<=511.5tcu3 | |
Honeywell Experion Server | >=520.1<=520.1tcu4 | |
Honeywell Experion Server | >=520.2<=520.2tcu2 | |
Honeywell Experion Station | >=501.1<=501.6hf8 | |
Honeywell Experion Station | >=510.1<=510.2hf12 | |
Honeywell Experion Station | >=511.1<=511.5tcu3 | |
Honeywell Experion Station | >=520.1<=520.1tcu4 | |
Honeywell Experion Station | >=520.2<=520.2tcu2 | |
Honeywell Engineering Station | >=510.1<=511.5tcu3 | |
Honeywell Engineering Station | >=520.1<=520.1tcu4 | |
Honeywell Engineering Station | >=520.2<=520.2tcu2 | |
Honeywell Direct Station | >=510.1<=511.5tcu3 | |
Honeywell Direct Station | >=520.1<=520.1tcu4 | |
Honeywell Direct Station | >=520.2<=520.2tcu2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23585 is a vulnerability that allows for a denial of service (DoS) attack on Honeywell Experion Server and Experion Station software.
CVE-2023-23585 works by exploiting a heap overflow vulnerability in the handling of a specially crafted message during a specific configuration operation.
CVE-2023-23585 has a severity rating of 7.5 out of 10, which is considered critical.
Versions between 501.1 and 501.6hf8, 510.1 and 510.2hf12, 511.1 and 511.5tcu3, and 520.1 and 520.2tcu2 of Honeywell Experion Server and Experion Station are affected by CVE-2023-23585.
To fix CVE-2023-23585, it is recommended to upgrade to a version of Honeywell Experion Server and Experion Station that is not affected by the vulnerability.