CVE-2025-2520

7.5

Honeywell · Experion PKS

Honeywell Experion PKS contains an uninitialized variable in Epic Platform Analyzer communications, which may allow an unauthenticated attacker to cause a denial of service.

Executive summary

An uninitialized variable vulnerability in Honeywell Experion PKS components poses a significant risk for denial of service attacks against critical industrial control systems.

Vulnerability

The vulnerability involves the use of an uninitialized variable within the Epic Platform Analyzer communications, which can be triggered by an unauthenticated attacker to cause a dereferencing of an uninitialized pointer, ultimately resulting in a denial of service.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting its potential to disrupt critical operational technology environments. Successful exploitation results in a denial of service, which can lead to significant system downtime, loss of visibility into industrial processes, and potential safety risks in affected facilities.

Remediation

Immediate Action: Administrators must update the affected Honeywell Experion PKS components to version 520.2 TCU9 HF1 or 530.1 TCU3 HF1 as specified by the vendor.

Proactive Monitoring: Security teams should monitor communication logs for anomalous traffic patterns or unexpected service restarts involving the Epic Platform Analyzer modules.

Compensating Controls: Deploy network segmentation and firewall rules to restrict access to the Epic Platform Analyzer communications, ensuring only authorized traffic reaches the affected controllers.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity of this vulnerability and its presence in industrial control software, organizations must prioritize the application of the vendor-provided hotfixes. Failure to patch these controllers leaves critical infrastructure susceptible to denial of service attacks, which could have severe operational consequences.

More Honeywell CVEs

Sources

Originally found and disclosed by Demid Uzenkov and Kirill Kutaev (Positive Technologies), per the CVE Program record.