CVE-2023-23585: Honeywell Direct Station

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.

Affected products

  • Honeywell Direct Station: from 510.1, up to and including 511.5tcu3; from 520.1, up to and including 520.1tcu4; from 520.2, up to and including 520.2tcu2
  • Honeywell Engineering Station: from 510.1, up to and including 511.5tcu3; from 520.1, up to and including 520.1tcu4; from 520.2, up to and including 520.2tcu2
  • Honeywell Experion Server: from 501.1, up to and including 501.6hf8; from 510.1, up to and including 510.2hf12; from 511.1, up to and including 511.5tcu3; from 520.1, up to and including 520.1tcu4; from 520.2, up to and including 520.2tcu2
  • Honeywell Experion Station: from 501.1, up to and including 501.6hf8; from 510.1, up to and including 510.2hf12; from 511.1, up to and including 511.5tcu3; from 520.1, up to and including 520.1tcu4; from 520.2, up to and including 520.2tcu2

Published 2023-07-13. Last modified 2026-06-17.