9.8

CVE-2023-25178

Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning. 

Data is provided by the National Vulnerability Database (NVD)
HoneywellC300 Firmware Version >= 501.1 <= 501.6hf8
   HoneywellC300 Version-
HoneywellC300 Firmware Version >= 510.1 <= 510.2hf12
   HoneywellC300 Version-
HoneywellC300 Firmware Version >= 511.1 <= 511.5tcu3
   HoneywellC300 Version-
HoneywellC300 Firmware Version >= 520.1 <= 520.1tcu4
   HoneywellC300 Version-
HoneywellC300 Firmware Version >= 520.2 <= 520.2tcu2
   HoneywellC300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.89% 0.746
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
psirt@honeywell.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.