CVE-2023-26597

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning. 

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
honeywellc300_firmware
501.1 ≤
𝑥
≤ 501.6hf8
honeywellc300_firmware
510.1 ≤
𝑥
≤ 510.2hf12
honeywellc300_firmware
511.1 ≤
𝑥
≤ 511.5tcu3
honeywellc300_firmware
520.1 ≤
𝑥
≤ 520.1tcu4
honeywellc300_firmware
520.2 ≤
𝑥
≤ 520.2tcu2
𝑥
= Vulnerable software versions