CVE-2025-2520: Dereferencing of an uninitialized pointer leads to denial of service.
The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications. An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which results in a dereferencing of an uninitialized pointer leading to a denial of service.
Honeywell recommends updating to the most recent version of
Honeywell Experion PKS: 520.2 TCU9 HF1and 530.1 TCU3 HF1. The affected Experion PKS products are
C300 PCNT02, EHB, EHPM, ELMM, Classic ENIM, ETN, FIM4, FIM8, PGM, and RFIM. The Experion PKS versions affected are from 520.1 through 520.2 TCU9 and from 530 through 530 TCU3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2520?
CVE-2025-2520 has been assessed to have a critical severity rating due to its potential to exploit communication vulnerabilities.
How do I fix CVE-2025-2520?
To fix CVE-2025-2520, it is recommended to update the Honeywell Experion PKS to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2025-2520?
The potential impacts of CVE-2025-2520 include communication channel manipulation and the dereferencing of uninitialized pointers.
Which versions of Honeywell Experion PKS are affected by CVE-2025-2520?
CVE-2025-2520 affects Honeywell Experion PKS versions from 520.1 to 520.2 TCU9 and from 530 to 530 TCU3.
Is CVE-2025-2520 actively being exploited?
As of the latest information, there are no confirmed reports of active exploitation of CVE-2025-2520.