CVE-2025-2521

8.6

Honeywell · Experion PKS and OneWireless WDM

Honeywell Experion PKS and OneWireless WDM contain a memory buffer vulnerability in the Control Data Access component that can lead to remote code execution.

Executive summary

A critical memory buffer vulnerability in Honeywell industrial control systems allows unauthenticated remote attackers to execute arbitrary code.

Vulnerability

This flaw involves improper restriction of operations within the bounds of a memory buffer in the Control Data Access component. An unauthenticated attacker can exploit this via network access to trigger an overread, potentially resulting in remote code execution.

Business impact

The exploitation of this vulnerability poses a severe risk to industrial operations, potentially leading to a complete compromise of the affected control systems. Given the CVSS score of 8.6, this represents a high-severity threat that could result in unauthorized data access, operational disruption, or loss of control over critical infrastructure processes.

Remediation

Immediate Action: Administrators must update Honeywell Experion PKS to version 520.2 TCU9 HF1 or 530.1 TCU3 HF1, and OneWireless WDM to version 322.5 or 331.1 immediately.

Proactive Monitoring: Monitor network traffic for unusual activity directed at the Control Data Access component and review system logs for signs of buffer overflow attempts or unexpected service restarts.

Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the affected devices, ensuring only authorized traffic can reach the Control Data Access service.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of these industrial control systems, immediate patching is required to prevent potential exploitation. Organizations should prioritize the deployment of the specified hotfixes and updates to ensure the integrity and availability of their control environment, as the lack of authentication requirements makes these systems highly susceptible to remote attack.

More Honeywell CVEs

Sources

Originally found and disclosed by Demid Uzenkov and Kirill Kutaev (Positive Technologies), per the CVE Program record.