CVE-2023-5389
CRITICALHoneywell Experion ControlEdge VirtualUOC and ControlEdge UOC - Fil...
Title source: llmDescription
An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
Scores
CVSS v3
9.1
EPSS
0.0013
EPSS Percentile
32.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-749
Status
published
Products (2)
honeywell/controledge_unit_operations_controller_firmware
honeywell/controledge_virtual_unit_operations_controller_firmware
Published
Jan 30, 2024
Tracked Since
Feb 18, 2026