CVE-2023-5389

CRITICAL

Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC - Fil...

Title source: llm
STIX 2.1

Description

An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. 

Scores

CVSS v3 9.1
EPSS 0.0013
EPSS Percentile 32.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-749
Status published
Products (2)
honeywell/controledge_unit_operations_controller_firmware
honeywell/controledge_virtual_unit_operations_controller_firmware
Published Jan 30, 2024
Tracked Since Feb 18, 2026