Honeywell Products是美国霍尼韦尔(Honeywell)公司的一系列产品。 Honeywell Products 存在安全漏洞,该漏洞源于 Experion 服务器 DoS 是由于在处理特定配置操作的特制消息期间发生堆溢出而导致的。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Honeywell | Experion Server | 501.1 ~ 501.6HF8 | - |
|
| Honeywell | Experion Station | 501.1 ~ 501.6HF8 | - |
|
| Honeywell | Engineering Station | 510.1 ~ 511.5TCU3 | - |
|
| Honeywell | Direct Station | 510.5 ~ 511.5TCU3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-25770 | 9.8 CRITICAL | Controller stack overflow on decoding messages from the server |
| CVE-2023-25178 | 9.8 CRITICAL | Controller design flaw - unsigned firmware |
| CVE-2023-25078 | 9.8 CRITICAL | DoS due to heap overflow |
| CVE-2023-24480 | 9.8 CRITICAL | Controller stack overflow when decoding messages from the server |
| CVE-2023-24474 | 7.5 HIGH | Server deserialization missing boundary checks - heap overflow in communication between se |
| CVE-2023-22435 | 7.5 HIGH | Server bad parsing implementation - stack overflow in server::get_db_path_for_driver |
| CVE-2023-26597 | 7.5 HIGH | Controller DOS on sending error response |
| CVE-2023-25948 | 7.5 HIGH | Server Data type confusion - info leak |
No comments yet