CVE-2016-8344 Information
Feb 14, 2021
cve
Description
An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS Release 3xx and prior Experion PKS Release 400 Experion PKS Release 410 Experion PKS Release 430 and Experion PKS Release 431. Experion PKS does not properly validate input. By sending a specially crafted packet an attacker could cause the process to terminate. A successful exploit would prevent firmware uploads to the Series-C devices.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Reference
http://www.securityfocus.com/bid/93950 https://ics-cert.us-cert.gov/advisories/ICSA-16-301-01
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
3.7
Share on: