CVE-2023-25948: Server Data type confusion - info leak
Published Jul 13, 2023
·Updated
Server information leak of configuration data when an error is generated in response to a specially crafted message.
Affected Software
16 affected components
Honeywell Experion server>=501.1<=501.6hf8
Honeywell Experion server>=510.1<=510.2hf12
Honeywell Experion server>=511.1<=511.5tcu3
Honeywell Experion server>=520.1<=520.1tcu4
Honeywell Experion server>=520.2<=520.2tcu2
Honeywell Experion Station>=501.1<=501.6hf8
Honeywell Experion Station>=510.1<=510.2hf12
Honeywell Experion Station>=511.1<=511.5tcu3
Honeywell Experion Station>=520.1<=520.1tcu4
Honeywell Experion Station>=520.2<=520.2tcu2
Honeywell Engineering Station>=510.1<=511.tcu3
Honeywell Engineering Station>=520.1<=520.1tcu4
Honeywell Engineering Station>=520.2<=520.2tcu2
Honeywell Direct Station>=510.1<=511.tcu3
Honeywell Direct Station>=520.1<=520.1tcu4
Honeywell Direct Station>=520.2<=520.2tcu2
Event History
Jul 13, 2023
CVE Published
via MITRE·11:09 AM
Data Sourced
via MITRE·11:09 AM
DescriptionSeverityWeakness
Data Sourced
12:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this server information leak of configuration data?
The vulnerability ID is CVE-2023-25948.
2
What is the severity level of CVE-2023-25948?
CVE-2023-25948 has a severity level of high.
3
Which software is affected by CVE-2023-25948?
Honeywell Experion Server, Honeywell Experion Station, Honeywell Engineering Station, and Honeywell Direct Station are affected by CVE-2023-25948.
4
How can the server information leak vulnerability be exploited?
This vulnerability can be exploited by generating an error with a specially crafted message.
5
Is there a fix for CVE-2023-25948?
Yes, it is recommended to apply the latest security patches provided by Honeywell to fix CVE-2023-25948.