Controller DoS due to stack overflow when decoding a message from the server. See Honeywell Security Notification for recommendations on upgrading and versioning.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHoneywell C300
HWHoneywellall versionsHoneywell C300 Firmware
OSHoneywell501.1 – 501.6hf8510.1 – 510.2hf12511.1 – 511.5tcu3520.1 – 520.1tcu4520.2 – 520.2tcu2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-25178CRITICAL9.8PL ✓same product
RCE poprzez złośliwy firmware w Honeywell C300
CVE-2023-25770CRITICAL9.8PL ✓same product
Honeywell C300: buffer overflow prowadzący do DoS kontrolera
CVE-2021-38395CRITICAL9.1PL ✓same product
RCE i DoS w sterownikach Honeywell Experion PKS poprzez injection w danych wyjściowych
CVE-2021-38397CRITICAL10.0PL ✓same product
Unrestricted file upload w kontrolerach Honeywell Experion PKS umożliwia RCE
CVE-2023-26597HIGH7.5same product
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controlle...