An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
An attacker, without requiring authentication and from the network level, can write or modify files on the Honeywell ControlEdge UOC or VirtualUOC controller. Writing a modified configuration or application file can result in unpredictable system behavior. In the event that the substituted file is subsequently executed by the system, malicious code execution is possible.
An attacker can permanently modify controller configuration or application files, which may lead to disruption of industrial processes or execution of malicious software on the device.
Software firmware should be updated to the latest version in accordance with Honeywell Security Notification recommendations available at https://process.honeywell.com and https://www.honeywell.com/us/en/product-security.
Honeywell ControlEdge UOC (Controledge Unit Operations Controller) and Honeywell ControlEdge VirtualUOC (Controledge Virtual Unit Operations Controller) — versions indicated in manufacturer references (Honeywell Security Notification).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HHoneywell Controledge Unit Operations Controller
HWHoneywellall versionsHoneywell Controledge Unit Operations Controller Firmware
OSHoneywellall versionsHoneywell Controledge Virtual Unit Operations Controller
HWHoneywellall versionsHoneywell Controledge Virtual Unit Operations Controller Firmware
OSHoneywellall versions
Related vulnerabilities
An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Exper...
Honeywell IQ4x — brak uwierzytelnienia w fabrycznym HMI (CWE-306)
OS Command Injection w Honeywell MB-Secure i MB-Secure PRO (privilege abuse)
Uwierzytelniony RCE w LenelS2 NetBox (wersje do 5.6.1 włącznie)
Nieuwierzytelniony RCE w Honeywell LenelS2 NetBox (command injection)