HIGH
Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failure
Published Apr 17, 2024
8.1
HIGHCVSS 3.1
EPSS 0.72%
Description
Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failure.
See Honeywell Security Notification for recommendations on upgrading and versioning.
Affected products
-
- Version 510.1StatusaffectedConstraints<=510.2 HF13
- Version 511.1StatusaffectedConstraints<=511.5 TCU4 HF3
- Version 520.1StatusaffectedConstraints<=520.1 TCU4
- Version 520.2StatusaffectedConstraints<=520.2 TCU4
- Version 520.2 TCU4 HFR2StatusaffectedConstraints<=511.5 TCU4 HF3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Honeywell | Experion Server | unaffected |
|
No data.
-
- Version 510.1StatusaffectedConstraints<=510.2_hf13
- Version 511.1StatusaffectedConstraints<=511.5_tcu4_hf3
- Version 511.5tcu4hf3StatusaffectedConstraints<=20.2tcu4hfr2
- Version 520.1StatusaffectedConstraints<=520.1_tcu4
- Version 520.2StatusaffectedConstraints<=520.2_tcu4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Honeywell | Experion Server | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
| Link | Providers | Tags |
|---|---|---|
| https://process.honeywell.com |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Honeywell
Published Apr 17, 2024
Updated Aug 29, 2024
Reserved Oct 4, 2023
Link CVE-2023-5403
CISA Vulnrichment
Updated Aug 7, 2024