Home
Description
Server communication with a controller can lead to remote code execution using a specially crafted message from the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.
PUBLISHED Reserved 2023-10-04 | Published 2024-04-17 | Updated 2024-08-02 | Assigner Honeywell
MEDIUM: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem types
CWE-787
Product status
Default status
unaffected
520.2
affected
510.1
affected
520.1
affected
511.1
affected
Default status
unaffected
520.2
affected
511.1
affected
520.1
affected
Default status
unaffected
520.2
affected
520.1
affected
520.2 TCU4 HFR2
affected
References
process.honeywell.com
cve.org
(CVE-2023-5406)
nvd.nist.gov
(CVE-2023-5406)
Download JSON