Vulnerability Description
Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Experion Server | >= 501.1, <= 501.6hf8 |
| Honeywell | Experion Station | >= 501.1, <= 501.6hf8 |
| Honeywell | Engineering Station | >= 510.1, <= 511.tcu3 |
| Honeywell | Direct Station | >= 510.1, <= 511.tcu3 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2023-25948?
CVE-2023-25948 is a vulnerability with a CVSS score of 7.5 (HIGH). Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning...
How severe is CVE-2023-25948?
CVE-2023-25948 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25948?
Check the references section above for vendor advisories and patch information. Affected products include: Honeywell Experion Server, Honeywell Experion Station, Honeywell Engineering Station, Honeywell Direct Station.