CVE Vulnerabilities

CVE-2023-25948

Unexpected Status Code or Return Value

Published: Jul 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

Weakness

The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.

Affected Software

Name Vendor Start Version End Version
Experion_server Honeywell 501.1 (including) 501.6hf8 (including)
Experion_server Honeywell 510.1 (including) 510.2hf12 (including)
Experion_server Honeywell 511.1 (including) 511.5tcu3 (including)
Experion_server Honeywell 520.1 (including) 520.1tcu4 (including)
Experion_server Honeywell 520.2 (including) 520.2tcu2 (including)

References