CVE-2023-5393 Vulnerability Details

  /     /     /  

CVE-2023-5393 Metadata Quick Info

CVE Published: 11/04/2024 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: Honeywell | Vendor: Honeywell | Product: Experion Server
Status : PUBLISHED

CVE-2023-5393 Description

Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

Metrics

CVSS Version: 3.1 | Base Score: 7.4 HIGH
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-130
CWE Name: CWE-130
Source: Honeywell

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-47
CAPEC Description: CAPEC-47


Source: NVD (National Vulnerability Database).