LOW🇬🇧 English

CVE-2016-8344

CVSS 3.7v3.0pub. 2017-02-13upd. 2026-05-13

Odkryto lukę w platformie Honeywell Experion Process Knowledge System (PKS): wersje 3xx i wcześniejsze, 400, 410, 430 i 431. Experion PKS nie waliduje prawidłowo danych wejściowych, co pozwala atakującemu na przesłanie specjalnie spreparowanego pakietu i spowodowanie terminu procesu. Pomyślny exploit uniemożliwi przesyłanie oprogramowania firmware'u do urządzeń Series-C.

Pokaż oryginał (EN)

An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS, Release 3xx and prior, Experion PKS, Release 400, Experion PKS, Release 410, Experion PKS, Release 430, and Experion PKS, Release 431. Experion PKS does not properly validate input. By sending a specially crafted packet, an attacker could cause the process to terminate. A successful exploit would prevent firmware uploads to the Series-C devices.

CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  • Honeywell Experion Process Knowledge System

    APP
    Honeywell
    410430431≤ 311≤ 411
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2014-5435CRITICAL9.8PL ✓ten sam produkt

Zapis do dowolnej pamięci w Honeywell Experion PKS — możliwe RCE

CVE-2014-9186CRITICAL9.8PL ✓ten sam produkt

File Inclusion w Honeywell Experion PKS — możliwy RCE

CVE-2014-9187CRITICAL9.8PL ✓ten sam produkt

Przepełnienie bufora sterty w Honeywell Experion PKS — RCE/DoS

CVE-2014-9189CRITICAL9.8PL ✓ten sam produkt

Stack-based buffer overflow w Honeywell Experion PKS — RCE i DoS

CVE-2014-5436HIGH7.5ten sam produkt

A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400....