CVE-2023-5392: Honeywell c300

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

Affected products

  • Honeywell c300: from 520.2, up to and including 520.2 TCU4; from 510.1, up to and including 510.2 HF13; from 520.1, up to and including 520.1 TCU4; from 511.1, up to and including 511.5 TCU4 HF3; from 520.2 TCU4 HFR2, up to and including 511.5 TCU4 HF3; from 510.1, up to and including 510.2_hf13; …

Published 2024-04-11. Last modified 2026-06-17.