CVE-2023-24474: Server deserialization missing boundary checks - heap overflow in communication between server and controller
Published Jul 13, 2023
·Updated
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
Affected Software
16 affected components
Honeywell Experion server>=501.1<=501.6hf8
Honeywell Experion server>=510.1<=510.2hf12
Honeywell Experion server>=511.1<=511.5tcu3
Honeywell Experion server>=520.1<=520.1tcu4
Honeywell Experion server>=520.2<=520.2tcu2
Honeywell Experion Station>=501.1<=501.6hf8
Honeywell Experion Station>=510.1<=510.2hf12
Honeywell Experion Station>=511.1<=511.5tcu3
Honeywell Experion Station>=520.1<=520.1tcu4
Honeywell Experion Station>=520.2<=520.2tcu2
Honeywell Engineering Station>=510.1<=511.5tcu3
Honeywell Engineering Station>=520.1<=520.1tcu4
Honeywell Engineering Station>=520.2<=520.2tcu2
Honeywell Direct Station>=510.1<=511.5tcu3
Honeywell Direct Station>=520.1<=520.1tcu4
Honeywell Direct Station>=520.2<=520.2tcu2
Event History
Jul 13, 2023
CVE Published
via MITRE·10:56 AM
Data Sourced
via MITRE·10:56 AM
DescriptionSeverityWeakness
Data Sourced
11:15 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-24474.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message'.
3
What software is affected by this vulnerability?
The Honeywell Experion Server, Experion Station, Engineering Station, and Direct Station are affected by this vulnerability.
4
How severe is this vulnerability?
This vulnerability has a severity rating of 7.5 (high).
5
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to install the latest security patch provided by Honeywell.