CVE-2023-5394: Buffer Overflow
Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5394?
CVE-2023-5394 has a high severity due to its potential for remote code execution.
How do I fix CVE-2023-5394?
To fix CVE-2023-5394, update to the most recent version of the affected Honeywell product as recommended.
What type of vulnerability is CVE-2023-5394?
CVE-2023-5394 is a stack overflow vulnerability caused by a malformed message with a large hostname.
What potential impact does CVE-2023-5394 have?
The potential impact of CVE-2023-5394 includes remote code execution, which can allow an attacker to execute arbitrary code on the server.
Which Honeywell products are affected by CVE-2023-5394?
CVE-2023-5394 affects certain undisclosed Honeywell products that are susceptible to malformed GCL messages.