CVE-2023-5407: Honeywell c300

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Controller denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.

Affected products

  • Honeywell c300: from 520.2, up to and including 520.2 TCU4; from 510.1, up to and including 510.2 HF13; from 520.1, up to and including 520.1 TCU4; from 511.1, up to and including 511.5 TCU4 HF3; from 520.2 TCU4 HFR2, up to and including 511.5 TCU4 HF3

Published 2024-04-17. Last modified 2026-06-17.