CVE-2023-25178

CRITICALCVSS 9.8/10EPSS 0.43%

Last modified

CVE-2023-25178 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning. . EPSS estimates a 0.43% chance of exploitation in the next 30 days.

Description

Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.43%

34.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HoneywellC300 Firmware>= 501.1, <= 501.6hf8
HoneywellC300 Firmware>= 510.1, <= 510.2hf12
HoneywellC300 Firmware>= 511.1, <= 511.5tcu3
HoneywellC300 Firmware>= 520.1, <= 520.1tcu4
HoneywellC300 Firmware>= 520.2, <= 520.2tcu2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-25178?
Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.
How severe is CVE-2023-25178?
CVE-2023-25178 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.43% probability of exploitation in the next 30 days.
How do I fix CVE-2023-25178?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-25178?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST