Vulnerabilidades em Honeywell

71 resultados
Análise Vexday

Com 70 CVEs catalogadas, o portfólio de vulnerabilidades da Honeywell apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem nenhum registro confirmado de exploração ativa no momento. Ainda assim, 14 falhas são classificadas como críticas, e o tipo de falha mais recorrente é CWE-121 (Stack-based Buffer Overflow), categoria historicamente associada a impactos severos em sistemas de controle industrial e automação. A CVE mais perigosa em destaque, CVE-2023-3710, concentra o maior escore EPSS observado no conjunto (0,33), indicando probabilidade relevante de exploração futura, especialmente considerando a existência de prova de conceito pública. Equipes de segurança que operam ambientes com tecnologias Honeywell devem priorizar a remediação das falhas críticas com PoC disponível, dado o perfil de risco elevado que essas combinações representam.

CVE-2023-51600MEDIUMHoneywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure VulnerabilityEPSS 0.8%CVE-2023-51605MEDIUMHoneywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure VulnerabilityEPSS 0.8%CVE-2023-51602MEDIUMHoneywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure VulnerabilityEPSS 0.8%CVE-2023-51604MEDIUMHoneywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure VulnerabilityEPSS 0.8%CVE-2023-51601MEDIUMHoneywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure VulnerabilityEPSS 0.8%CVE-2023-5389CRITICAL An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUEPSS 0.8%CVE-2023-5397HIGHServer receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failEPSS 0.8%CVE-2021-38399HIGHHoneywell Experion PKS and ACE Controllers Relative Path TraversalEPSS 0.8%CVE-2023-5395HIGHServer receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in possible remote codEPSS 0.7%CVE-2023-5400HIGHServer receiving a malformed message based on a using the specified key values can cause a heap overflow vulnerability which could lead to aEPSS 0.7%CVE-2023-5401HIGHServer receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to EPSS 0.7%CVE-2023-5404HIGHServer receiving a malformed message can cause a pointer to be overwritten which can result in a remote code execution or failure. See HoneyEPSS 0.7%CVE-2023-5403HIGHServer hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failureEPSS 0.7%CVE-2023-24480CRITICALController stack overflow when decoding messages from the serverEPSS 0.7%CVE-2023-25770CRITICALController stack overflow on decoding messages from the serverEPSS 0.7%CVE-2023-5394HIGHServer receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in posEPSS 0.7%CVE-2023-5393HIGHServer receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code eEPSS 0.7%CVE-2023-5396HIGHServer receiving a malformed message creates connection for a hostname that may cause a stack overflow resulting in possible remote code exeEPSS 0.7%CVE-2023-5406MEDIUMServer communication with a controller can lead to remote code execution using a specially crafted message from the controller. See HoneywelEPSS 0.7%CVE-2025-2523CRITICALLack of buffer clearing before reuse may result in incorrect system behavior.EPSS 0.7%