VYPR

Experion

by Honeywell

CVEs (16)

  • CVE-2021-38397CriOct 28, 2022
    risk 0.65cvss 10.0epss 0.01

    Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.

  • CVE-2023-25078CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-23585CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2014-9186CriApr 8, 2019
    risk 0.64cvss 9.8epss 0.04

    A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code…

  • CVE-2014-5435CriApr 8, 2019
    risk 0.64cvss 9.8epss 0.03

    An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote code execution or denial of service. Honeywell strongly encourages and…

  • CVE-2014-9189CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.05

    Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that could lead to possible remote code execution, dynamic memory corruption, or denial…

  • CVE-2014-9187CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.04

    Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could lead to possible remote code execution or denial of service. Honeywell strongly…

  • CVE-2021-38395CriOct 28, 2022
    risk 0.59cvss 9.1epss 0.01

    Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.

  • CVE-2022-30317CriAug 31, 2022
    risk 0.59cvss 9.1epss 0.01

    Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experion LX Control Data Access (CDA) EpicMo protocol with unauthenticated functionality issue. The affected components are…

  • CVE-2023-25948HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-24474HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message

  • CVE-2023-22435HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.

  • CVE-2021-38399HigOct 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.

  • CVE-2022-30313HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a Honeywell Experion PKS Safety Manager multiple proprietary protocols with unauthenticated functionality issue. The affected…

  • CVE-2014-5436HigApr 8, 2019
    risk 0.49cvss 7.5epss 0.03

    A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to possible information disclosure. Honeywell strongly encourages and recommends all customers running…

  • CVE-2012-0254Sep 8, 2012
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in the HMIWeb Browser HSCDSPRenderDLL ActiveX control in Honeywell Process Solutions (HPS) Experion R2xx, R30x, R31x, and R400.x; Honeywell Building Solutions (HBS) Enterprise Building Manager R400 and R410.1; and Honeywell Environmental Combustion…