CVE-2023-24474 describes a heap overflow vulnerability in Honeywell Experion Server, Direct Station, Engineering Station, and Experion Station, which can lead to a Denial of Service (DoS) when processing specially crafted messages. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity and no user interaction, resulting in high availability impact. While there is no evidence of active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, including an article from SecurityWeek. Organizations using affected Honeywell products should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 501.1, <= 501.6hf8CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_server:*:*:*:*:*:*:*:* | ||
>= 510.1, <= 510.2hf12CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_server:*:*:*:*:*:*:*:* | ||
>= 511.1, <= 511.5tcu3CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_server:*:*:*:*:*:*:*:* | ||
>= 520.1, <= 520.1tcu4CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_server:*:*:*:*:*:*:*:* | ||
>= 520.2, <= 520.2tcu2CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.