CVE-2023-5389
CRITICALHoneywell Experion ControlEdge VirtualUOC and ControlEdge UOC - Fil...
Title source: llmDescription
An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
References (2)
Core 2
Core References
Product
https://process.honeywell.com
Not Applicable
https://www.honeywell.com/us/en/product-security
Scores
CVSS v3
9.1
EPSS
0.0078
EPSS Percentile
50.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-749
Status
published
Products (2)
honeywell/controledge_unit_operations_controller_firmware
honeywell/controledge_virtual_unit_operations_controller_firmware
Published
Jan 30, 2024
Tracked Since
Feb 18, 2026