CVE-2016-8344 is an input validation vulnerability affecting multiple releases of the Honeywell Experion Process Knowledge System (PKS) platform. An unauthenticated attacker can send a specially crafted network packet to cause a denial of service, terminating a process and preventing firmware uploads to Series-C devices. While the attack vector is network-based, the attack complexity is high, resulting in a low CVSS score of 3.7. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 311CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_process_knowledge_system:*:*:*:*:*:*:*:* | ||
410CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_process_knowledge_system:410:*:*:*:*:*:*:* | ||
430CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_process_knowledge_system:430:*:*:*:*:*:*:* | ||
431CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_process_knowledge_system:431:*:*:*:*:*:*:* | ||
<= 411CPE matchmatch criteria | cpe:2.3:a:honeywell:experion_process_knowledge_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.