First published: Tue Jan 30 2024(Updated: )
An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
Credit: psirt@honeywell.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Honeywell Controledge Unit Operations Controller Firmware | ||
Honeywell Controledge Unit Operations Controller | ||
All of | ||
Honeywell Controledge Virtual Unit Operations Controller Firmware | ||
Honeywell Controledge Virtual Unit Operations Controller |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5389 is classified as a high-severity vulnerability due to the potential for unauthorized file modifications.
To fix CVE-2023-5389, update the Honeywell Controledge firmware to the latest version available from the manufacturer.
CVE-2023-5389 affects the Honeywell ControlEdge Virtual UOC and ControlEdge Unit Operations Controller firmware.
Exploiting CVE-2023-5389 could lead to unauthorized file modifications that may cause unexpected behavior in control systems.
Currently, the best recommendation for CVE-2023-5389 is to apply the firmware updates as no specific workarounds are provided.