7.5

CVE-2023-26597

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning. 

Data is provided by the National Vulnerability Database (NVD)
HoneywellC300 Firmware Version >= 501.1 <= 501.6hf8
   HoneywellC300 Version-
HoneywellC300 Firmware Version >= 510.1 <= 510.2hf12
   HoneywellC300 Version-
HoneywellC300 Firmware Version >= 511.1 <= 511.5tcu3
   HoneywellC300 Version-
HoneywellC300 Firmware Version >= 520.1 <= 520.1tcu4
   HoneywellC300 Version-
HoneywellC300 Firmware Version >= 520.2 <= 520.2tcu2
   HoneywellC300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.159
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
psirt@honeywell.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.