CVE-2016-8344
By sending a specially crafted packet, an attacker could cause the process to terminate.
Does this matter?
Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS, Release 3xx and prior, Experion PKS, Release 400, Experion PKS, Release 410, Experion PKS, Release 430, and Experion PKS, Release 431. Experion PKS does not properly validate input. By sending a specially crafted packet, an attacker could cause the process to terminate. A successful exploit would prevent firmware uploads to the Series-C devices.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- honeywell/experion process knowledge system
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/93950Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-301-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/93950Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-301-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.