CVE-2023-5390: Path Traversal
An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limited information from the device. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5390?
CVE-2023-5390 is classified as a moderate severity vulnerability.
How do I fix CVE-2023-5390?
To address CVE-2023-5390, update the firmware of the Honeywell Controledge Unit Operations Controller and Virtual Unit Operations Controller to the latest version.
What could be the impact of exploiting CVE-2023-5390?
Exploiting CVE-2023-5390 could allow an attacker to read limited files from the Honeywell controllers, potentially exposing sensitive information.
Who is affected by CVE-2023-5390?
CVE-2023-5390 affects users of the Honeywell Controledge Unit Operations Controller and Controledge Virtual Unit Operations Controller firmware.
Is there a workaround for CVE-2023-5390?
There are no known workarounds for CVE-2023-5390; the recommended action is to apply the firmware updates.