CVE-2023-24480: Controller stack overflow when decoding messages from the server
Published Jul 13, 2023
·Updated
Controller DoS due to stack overflow when decoding a message from the server
Affected Software
12 affected components
Honeywell C300 Firmware>=501.1<=501.6hf8
Honeywell C300 Firmware>=510.1<=510.2hf12
Honeywell C300 Firmware>=511.1<=511.5tcu3
Honeywell C300 Firmware>=520.1<=520.1tcu4
Honeywell C300 Firmware>=520.2<=520.2tcu2
Honeywell C300
All of the following
Any of the following
Honeywell C300 Firmware>=501.1<=501.6hf8
Honeywell C300 Firmware>=510.1<=510.2hf12
Honeywell C300 Firmware>=511.1<=511.5tcu3
Honeywell C300 Firmware>=520.1<=520.1tcu4
Honeywell C300 Firmware>=520.2<=520.2tcu2
Honeywell C300
Event History
Jul 13, 2023
CVE Published
via MITRE·10:57 AM
Data Sourced
via MITRE·10:57 AM
DescriptionSeverityWeakness
Data Sourced
11:15 AM
Description
Frequently Asked Questions
1
What is CVE-2023-24480?
CVE-2023-24480 is a vulnerability that allows for a denial-of-service attack on the controller due to a stack overflow when decoding a message from the server.
2
What is the severity of CVE-2023-24480?
The severity of CVE-2023-24480 is critical with a severity value of 7.5.
3
Which software versions are affected by CVE-2023-24480?
The Honeywell C300 Firmware versions between 501.1 and 501.6hf8, 510.1 and 510.2hf12, 511.1 and 511.5tcu3, and 520.1 and 520.1tcu4 are affected by CVE-2023-24480.
4
How can the CVE-2023-24480 vulnerability be exploited?
The CVE-2023-24480 vulnerability can be exploited by sending a specially crafted message from the server to trigger a stack overflow in the controller.
5
Is the Honeywell C300 device vulnerable to CVE-2023-24480?
No, the Honeywell C300 device itself is not vulnerable to CVE-2023-24480, only specific firmware versions are affected.