CVE-2023-26597

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller.See Honeywell Security Notification for recommendations on upgrading and versioning.See Honeywell Security Notification for recommendations on upgrading and versioning. 

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
HoneywellCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
VendorProductVersion
honeywellc300_firmware
501.1 ≤
𝑥
≤ 501.6hf8
honeywellc300_firmware
510.1 ≤
𝑥
≤ 510.2hf12
honeywellc300_firmware
511.1 ≤
𝑥
≤ 511.5tcu3
honeywellc300_firmware
520.1 ≤
𝑥
≤ 520.1tcu4
honeywellc300_firmware
520.2 ≤
𝑥
≤ 520.2tcu2
𝑥
= Vulnerable software versions