nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-5392 CVE-2023-5392
HIGH
Record summary
CVE-2023-5392 has a selected CVSS score of 7.5 (high).
Description
C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 8, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 520.2 to ≤ 520.2 TCU4 | affected |
| 510.1 to ≤ 510.2 HF13 | affected | ||
| 520.1 to ≤ 520.1 TCU4 | affected | ||
| 511.1 to ≤ 511.5 TCU4 HF3 | affected | ||
| 520.2 TCU4 HFR2 to ≤ 511.5 TCU4 HF3 | affected | ||
| 510.1 to ≤ 510.2_hf13 | affected | ||
| 511.1 to ≤ 511.5_tcu4_hf3 | affected | ||
| 520.1 to ≤ 520.1_tcu4 | affected | ||
| 520.2 to ≤ 520.2_tcu4 | affected | ||
| 520.2_tcu4_hfr2 to ≤ 511.5_tcu4_hf3 | affected |
References
2process.honeywell.com
https://process.honeywell.com/