{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-5392","assignerOrgId":"0dc86260-d7e3-4e81-ba06-3508e030ce8d","state":"PUBLISHED","assignerShortName":"Honeywell","dateReserved":"2023-10-04T17:50:45.390Z","datePublished":"2024-04-11T19:19:19.070Z","dateUpdated":"2024-08-02T07:59:44.280Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Experion PKS"],"product":"C300","vendor":"Honeywell","versions":[{"lessThanOrEqual":"520.2 TCU4","status":"affected","version":"520.2","versionType":"semver"},{"lessThanOrEqual":"510.2 HF13","status":"affected","version":"510.1","versionType":"semver"},{"lessThanOrEqual":"520.1 TCU4","status":"affected","version":"520.1","versionType":"semver"},{"lessThanOrEqual":"511.5 TCU4 HF3","status":"affected","version":"511.1","versionType":"semver"}]},{"defaultStatus":"unaffected","platforms":["Experion LX"],"product":"C300","vendor":"Honeywell","versions":[{"lessThanOrEqual":"520.2 TCU4","status":"affected","version":"520.2","versionType":"semver"},{"lessThanOrEqual":"511.5 TCU4 HF3","status":"affected","version":"511.1","versionType":"semver"},{"lessThanOrEqual":"520.1 TCU4","status":"affected","version":"520.1","versionType":"semver"}]},{"defaultStatus":"unaffected","platforms":["PlantCruise by Experion"],"product":"C300","vendor":"Honeywell","versions":[{"lessThanOrEqual":"520.2 TCU4","status":"affected","version":"520.2","versionType":"semver"},{"lessThanOrEqual":"520.1 TCU4","status":"affected","version":"520.1","versionType":"semver"},{"lessThanOrEqual":"511.5 TCU4 HF3","status":"affected","version":"520.2 TCU4 HFR2","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function.&nbsp;Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. \n\n"}],"value":"C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. \n\n"}],"impacts":[{"capecId":"CAPEC-121","descriptions":[{"lang":"en","value":"CAPEC-121"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1295","description":"CWE-1295","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"0dc86260-d7e3-4e81-ba06-3508e030ce8d","shortName":"Honeywell","dateUpdated":"2024-04-25T16:53:35.336Z"},"references":[{"url":"https://process.honeywell.com"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"affected":[{"vendor":"honeywell","product":"c300","cpes":["cpe:2.3:h:honeywell:c300:-:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"510.1","status":"affected","lessThanOrEqual":"510.2_hf13","versionType":"semver"},{"version":"511.1","status":"affected","lessThanOrEqual":"511.5_tcu4_hf3","versionType":"semver"},{"version":"520.1","status":"affected","lessThanOrEqual":"520.1_tcu4","versionType":"semver"},{"version":"520.2","status":"affected","lessThanOrEqual":"520.2_tcu4","versionType":"semver"},{"version":"520.2_tcu4_hfr2","status":"affected","lessThanOrEqual":"511.5_tcu4_hf3","versionType":"semver"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-08T18:49:08.032838Z","id":"CVE-2023-5392","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-08T20:14:06.723Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T07:59:44.280Z"},"title":"CVE Program Container","references":[{"url":"https://process.honeywell.com","tags":["x_transferred"]}]}]}}