CVE-2023-5394: Honeywell Experion Lx
High severity, CVSS 7.4. EPSS: 0.7% chance of exploitation in the next 30 days.
Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
Affected products
- Honeywell Experion Lx: from 520.2, up to and including 520.2 TCU4; from 511.1, up to and including 511.5 TCU4 HF3; from 520.1, up to and including 520.1 TCU4
- Honeywell Experion Process Knowledge System: from 520.2, up to and including 520.2 TCU4; from 510.1, up to and including 510.2 HF13; from 520.1, up to and including 520.1 TCU4; from 511.1, up to and including 511.5 TCU4 HF3
- Honeywell Experion Server: from 520.2, up to and including 520.2 TCU4; from 510.1, up to and including 510.2 HF13; from 520.1, up to and including 520.1 TCU4; from 511.1, up to and including 511.5 TCU4 HF3; from 520.2 TCU4 HFR2, up to and including 511.5 TCU4 HF3
- Honeywell Plantcruise: from 520.2, up to and including 520.2 TCU4; from 520.1, up to and including 520.1 TCU4; from 520.2 TCU4 HFR2, up to and including 511.5 TCU4 HF3
Published 2024-04-11. Last modified 2026-06-17.