CVE-2014-9186 describes a critical file inclusion vulnerability in the confd.exe module of Honeywell Experion PKS R40x, R41x, and R43x versions prior to their respective patches. This flaw allows an attacker to inject arbitrary files, potentially leading to information disclosure or remote code execution. With a CVSS score of 9.8 (Critical) and a FAUCET Risk Score of 93/100, it poses a significant threat due to its network-exploitable nature with low attack complexity and no user interaction required. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered considerable community discussion, indicated by 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r400, < r400.6CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_process_knowledge_system:*:*:*:*:*:*:*:* | ||
>= r410, < r410.6CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_process_knowledge_system:*:*:*:*:*:*:*:* | ||
>= r430, < r430.2CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_process_knowledge_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.