CVE-2023-5390
An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC.
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limited information from the device. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-36, CWE-22
- Affected
- honeywell/controledge unit operations controller firmware · honeywell/controledge virtual unit operations controller firmware
- Source
- psirt@honeywell.com
References
- https://process.honeywell.comProduct
- https://www.honeywell.com/us/en/product-securityNot Applicable
- https://process.honeywell.comProduct
- https://www.honeywell.com/us/en/product-securityNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.