Honeywell Products是美国霍尼韦尔(Honeywell)公司的一系列产品。 Honeywell Products 存在安全漏洞,该漏洞源于在处理特定配置操作的特制消息期间发生堆溢出,导致服务器或控制台站 DoS。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Honeywell | Experion Server | 501.1 ~ 501.6HF8 | - |
|
| Honeywell | Experion Station | 501.1 ~ 501.6HF8 | - |
|
| Honeywell | Engineering Station | 510.1 ~ 511.5TCU3 | - |
|
| Honeywell | Direct Station | 510.5 ~ 511.5TCU3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-25770 | 9.8 CRITICAL | Controller stack overflow on decoding messages from the server |
| CVE-2023-25178 | 9.8 CRITICAL | Controller design flaw - unsigned firmware |
| CVE-2023-24480 | 9.8 CRITICAL | Controller stack overflow when decoding messages from the server |
| CVE-2023-23585 | 9.8 CRITICAL | Server DoS due to heap overflow |
| CVE-2023-24474 | 7.5 HIGH | Server deserialization missing boundary checks - heap overflow in communication between se |
| CVE-2023-22435 | 7.5 HIGH | Server bad parsing implementation - stack overflow in server::get_db_path_for_driver |
| CVE-2023-26597 | 7.5 HIGH | Controller DOS on sending error response |
| CVE-2023-25948 | 7.5 HIGH | Server Data type confusion - info leak |
No comments yet