CVE-2023-25178
CRITICALHoneywell C300 Firmware < 501.6hf8 - Data Authenticity Bypass
Title source: ruleDescription
Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.
References (1)
Scores
CVSS v3
9.8
EPSS
0.0119
EPSS Percentile
78.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-345
Status
published
Products (1)
honeywell/c300_firmware
501.1 - 501.6hf8
Published
Jul 13, 2023
Tracked Since
Feb 18, 2026