nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-5398 CVE-2023-5398
MEDIUM
Record summary
CVE-2023-5398 has a selected CVSS score of 5.9 (medium).
Description
Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. See Honeywell Security Notification for recommendations on upgrading and versioning.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 19, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Experion ServerBrowse Honeywell / Experion ServerDefault status: unaffected, unknown | CVE List | 520.2 to ≤ 520.2 TCU4 | affected |
| 510.1 to ≤ 510.2 HF13 | affected | ||
| 520.1 to ≤ 520.1 TCU4 | affected | ||
| 511.1 to ≤ 511.5 TCU4 HF3 | affected | ||
| 520.2 TCU4 HFR2 to ≤ 511.5 TCU4 HF3 | affected | ||
| 520.2 to ≤ 520.2_tcu4 | affected | ||
| 510.1 to ≤ 510.2_hf13 | affected | ||
| 520.1 to ≤ 520.1_tcu4 | affected | ||
| 511.1 to ≤ 511.5_tcu4_hf3 | affected |
References
2process.honeywell.com
https://process.honeywell.com/