Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.34%—Honeywell Experion PKSAI10/7/202517/6/2026
The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in improper integer data value checking during subtraction leading to a denial of service.…
AplazadaAlta (8.2)0.52%—Honeywell Experion PKSAIHoneywell Onewireless WDMAI10/7/202517/6/2026
The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in incorrect handling of packets leading to remote code…
AplazadaCrítica (9.4)0.76%—Honeywell Experion PKSAIHoneywell Onewireless WDMAI10/7/202517/6/2026
The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in a failure during subtraction allowing remote code…
AplazadaMedia (6.5)0.25%—Honeywell Experion PKSAIHoneywell Onewireless WDMAI10/7/202517/6/2026
The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect…
AplazadaAlta (8.6)0.47%—Honeywell Experion PKSAIHoneywell Onewireless WDMAI10/7/202517/6/2026
The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to an Overread Buffers, which could result in improper index validation against buffer borders leading to remote code…
AplazadaAlta (7.5)0.39%—Honeywell Experion PKSAI10/7/202517/6/2026
The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications. An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which results in a dereferencing of an uninitialized pointer leading to a denial of…
ModificadaAlta (7.5)0.57%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.65%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.66%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
ModificadaAlta (7.5)0.65%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.60%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
ModificadaCrítica (9.1)0.87%—Honeywell Experion LX Firmware31/8/202217/6/2026
Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experion LX Control Data Access (CDA) EpicMo protocol with unauthenticated functionality issue. The affected components are characterized as: Honeywell Control Data Access…
ModificadaCrítica (9.8)3.6%—Honeywell Experion Process Knowledge System8/4/201917/6/2026
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code execution. Honeywell strongly encourages and…
ModificadaAlta (7.5)3.1%—Honeywell Experion Process Knowledge System8/4/201917/6/2026
A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to possible information disclosure. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400…
ModificadaCrítica (9.8)3.5%—Honeywell Experion Process Knowledge System8/4/201917/6/2026
An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recommends all customers running unsupported…
ModificadaCrítica (9.8)5.2%—Honeywell Experion Process Knowledge System25/3/201917/6/2026
Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that could lead to possible remote code execution, dynamic memory corruption, or denial of service. Honeywell strongly…
ModificadaCrítica (9.8)3.6%—Honeywell Experion Process Knowledge System25/3/201917/6/2026
Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recommends all customers…
ModificadaBaja (3.7)1.5%—Honeywell Experion Process Knowledge System13/2/201717/6/2026
An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS, Release 3xx and prior, Experion PKS, Release 400, Experion PKS, Release 410, Experion PKS, Release 430, and Experion PKS, Release 431. Experion PKS does not properly validate input. By sending a specially crafted…
ModificadaAlta (7.5)4.1%—Honeywell Enterprise Building ManagerHoneywell ExperionHoneywell Symmetre8/9/201216/6/2026
Stack-based buffer overflow in the HMIWeb Browser HSCDSPRenderDLL ActiveX control in Honeywell Process Solutions (HPS) Experion R2xx, R30x, R31x, and R400.x; Honeywell Building Solutions (HBS) Enterprise Building Manager R400 and R410.1; and Honeywell Environmental Combustion and Controls (ECC) SymmetrE R410.1 allows…
Orbitaley — Vulnerabilidades