CVE-2023-5389: Honeywell Controledge Unit Operations Controller Firmware

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. 

Affected products

  • Honeywell Controledge Unit Operations Controller Firmware: affected versions not specified
  • Honeywell Controledge Virtual Unit Operations Controller Firmware: affected versions not specified

Published 2024-01-30. Last modified 2026-06-17.