CRITICAL🇵🇱 Wersja polska

CVE-2014-9186

CVSS 9.8v3.0pub. 2019-04-08upd. 2024-11-21

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code execution. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Honeywell Experion Process Knowledge System

    APP
    Honeywell
    r400 – r400.6 (excl.)r410 – r410.6 (excl.)r430 – r430.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2014-5435CRITICAL9.8PL ✓same product

Zapis do dowolnej pamięci w Honeywell Experion PKS — możliwe RCE

CVE-2014-9187CRITICAL9.8PL ✓same product

Przepełnienie bufora sterty w Honeywell Experion PKS — RCE/DoS

CVE-2014-9189CRITICAL9.8PL ✓same product

Stack-based buffer overflow w Honeywell Experion PKS — RCE i DoS

CVE-2014-5436HIGH7.5same product

A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400....

CVE-2016-8344LOW3.7same product

Odkryto lukę w platformie Honeywell Experion Process Knowledge System (PKS): wersje 3xx i wcześniejsze, 400, 4...