CVE-2023-5395: Honeywell Experion Server

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Server receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

Affected products

  • Honeywell Experion Server: from 520.2, up to and including 520.2 TCU4; from 510.1, up to and including 510.2 HF13; from 520.1, up to and including 520.1 TCU4; from 511.1, up to and including 511.5 TCU4 HF3; from 520.2 TCU4 HFR2, up to and including 511.5 TCU4 HF3; from 520.2, up to and including 520.2_tcu4; …

Published 2024-04-17. Last modified 2026-06-17.