CRITICAL🇵🇱 Wersja polska

CVE-2023-5389

CVSS 9.1v3.1pub. 2024-01-30upd. 2024-11-21

An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. 

🤖 AI Analysis
How it works

An attacker, without requiring authentication and from the network level, can write or modify files on the Honeywell ControlEdge UOC or VirtualUOC controller. Writing a modified configuration or application file can result in unpredictable system behavior. In the event that the substituted file is subsequently executed by the system, malicious code execution is possible.

Impact

An attacker can permanently modify controller configuration or application files, which may lead to disruption of industrial processes or execution of malicious software on the device.

Mitigation & patch

Software firmware should be updated to the latest version in accordance with Honeywell Security Notification recommendations available at https://process.honeywell.com and https://www.honeywell.com/us/en/product-security.

Who is affected

Honeywell ControlEdge UOC (Controledge Unit Operations Controller) and Honeywell ControlEdge VirtualUOC (Controledge Virtual Unit Operations Controller) — versions indicated in manufacturer references (Honeywell Security Notification).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Honeywell Controledge Unit Operations Controller

    HW
    Honeywell
    all versions
  • Honeywell Controledge Unit Operations Controller Firmware

    OS
    Honeywell
    all versions
  • Honeywell Controledge Virtual Unit Operations Controller

    HW
    Honeywell
    all versions
  • Honeywell Controledge Virtual Unit Operations Controller Firmware

    OS
    Honeywell
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-5390MEDIUM5.3same product

An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Exper...

CVE-2026-3611CRITICAL10.0PL ✓same vendor

Honeywell IQ4x — brak uwierzytelnienia w fabrycznym HMI (CWE-306)

CVE-2025-2605CRITICAL9.9PL ✓same vendor

OS Command Injection w Honeywell MB-Secure i MB-Secure PRO (privilege abuse)

CVE-2024-2422CRITICAL9.3PL ✓same vendor

Uwierzytelniony RCE w LenelS2 NetBox (wersje do 5.6.1 włącznie)

CVE-2024-2421CRITICAL9.3PL ✓same vendor

Nieuwierzytelniony RCE w Honeywell LenelS2 NetBox (command injection)