« Volver al listado

CVE-2023-26597

Estado: ModificadaAlta (7.5)—

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-26597",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-26597",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-05T18:38:43.280343Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@honeywell.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@honeywell.com",
      "affectedData": [
        {
          "vendor": "Honeywell",
          "product": "C300",
          "versions": [
            {
              "status": "affected",
              "version": "501.1",
              "versionType": "semver",
              "lessThanOrEqual": "501.6HF8"
            },
            {
              "status": "affected",
              "version": "510.1",
              "versionType": "semver",
              "lessThanOrEqual": "510.2HF12"
            },
            {
              "status": "affected",
              "version": "511.1",
              "versionType": "semver",
              "lessThanOrEqual": "511.5TCU3"
            },
            {
              "status": "affected",
              "version": "520.1",
              "versionType": "semver",
              "lessThanOrEqual": "520.1TCU4"
            },
            {
              "status": "affected",
              "version": "520.2",
              "versionType": "semver",
              "lessThanOrEqual": "520.2TCU2"
            }
          ],
          "platforms": [
            "Experion PKS"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Honeywell",
          "product": "C300",
          "versions": [
            {
              "status": "affected",
              "version": "510.1",
              "versionType": "semver",
              "lessThanOrEqual": "511.5TCU3"
            },
            {
              "status": "affected",
              "version": "520.1",
              "versionType": "semver",
              "lessThanOrEqual": "520.1TCU4"
            },
            {
              "status": "affected",
              "version": "520.2",
              "versionType": "semver",
              "lessThanOrEqual": "520.2TCU2"
            }
          ],
          "platforms": [
            "Experion LX",
            "Experion PlantCruise"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-07-13T12:15:09.253",
  "references": [
    {
      "url": "https://process.honeywell.com",
      "tags": [
        "Product"
      ],
      "source": "psirt@honeywell.com"
    },
    {
      "url": "https://process.honeywell.com",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@honeywell.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning. \n\n"
    }
  ],
  "lastModified": "2026-06-17T05:43:40.827",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:honeywell:c300_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8B1523A-A717-4BE3-97B1-5634188EAAF9",
              "versionEndIncluding": "501.6hf8",
              "versionStartIncluding": "501.1"
            },
            {
              "criteria": "cpe:2.3:o:honeywell:c300_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F01D307E-1DD4-4B16-A1EF-81503E5C7CF1",
              "versionEndIncluding": "510.2hf12",
              "versionStartIncluding": "510.1"
            },
            {
              "criteria": "cpe:2.3:o:honeywell:c300_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AAAF640-4704-4BEA-AB36-911B08227497",
              "versionEndIncluding": "511.5tcu3",
              "versionStartIncluding": "511.1"
            },
            {
              "criteria": "cpe:2.3:o:honeywell:c300_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "254FC5F7-6F70-4E38-95B8-E0042AB3321F",
              "versionEndIncluding": "520.1tcu4",
              "versionStartIncluding": "520.1"
            },
            {
              "criteria": "cpe:2.3:o:honeywell:c300_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F075CA91-AFC8-4463-9D02-BE45F98E4840",
              "versionEndIncluding": "520.2tcu2",
              "versionStartIncluding": "520.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:honeywell:c300:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CEA14D67-E320-490E-92E6-CC135EBBA245"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@honeywell.com"
}