CVE-2023-25078: DoS due to heap overflow
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25078?
CVE-2023-25078 is a vulnerability that allows for a denial-of-service attack due to a heap overflow during the handling of a specially crafted message for a specific configuration operation.
Which software is affected by CVE-2023-25078?
Honeywell Experion Server (versions 501.1 to 501.6hf8, 510.1 to 510.2hf12, 51.1 to 511.5tcu3, 520.1 to 520.1tcu4, 520.2 to 520.2tcu2), Honeywell Experion Station (versions 501.1 to 501.6hf8, 510.1 to 510.2hf12, 511.1 to 511.5tcu3, 520.1 to 520.1tcu4, 520.2 to 520.2tcu2), Honeywell Engineering Station (versions 510.1 to 511.tcu3, 520.1 to 520.1tcu4, 520.2 to 520.2tcu2), and Honeywell Direct Station (versions 510.1 to 511.tcu3, 520.1 to 520.1tcu4, 520.2 to 520.2tcu2) are affected by CVE-2023-25078.
What is the severity of CVE-2023-25078?
CVE-2023-25078 has a severity rating of 7.5, which is considered critical.
How can I fix CVE-2023-25078?
To fix CVE-2023-25078, it is recommended to install the latest security updates provided by Honeywell for the affected software versions.
Where can I find more information about CVE-2023-25078?
You can find more information about CVE-2023-25078 on the Honeywell website at https://process.honeywell.com.