CVE-2025-3946

8.2

Honeywell · Experion PKS, OneWireless WDM

Honeywell Experion PKS and OneWireless WDM contain a deployment of wrong handler vulnerability in the Control Data Access component that can lead to remote code execution.

Executive summary

A vulnerability in the Honeywell Control Data Access component allows unauthenticated attackers to manipulate input data, potentially resulting in remote code execution.

Vulnerability

The flaw involves a deployment of wrong handler (CWE-430) within the Control Data Access component. An unauthenticated attacker can exploit this to perform input data manipulation, which triggers incorrect packet handling and facilitates remote code execution.

Business impact

Successful exploitation of this vulnerability poses a severe risk to industrial control environments, as it allows unauthorized remote code execution on critical infrastructure components. Given the CVSS score of 8.2, the high impact on system integrity and availability necessitates immediate attention. Compromise of these systems could lead to significant operational disruption, loss of control over industrial processes, and potential safety hazards.

Remediation

Immediate Action: Update Honeywell Experion PKS to version 520.2 TCU9 HF1 or 530.1 TCU3 HF1, and update OneWireless WDM to version 322.5 or 331.1.

Proactive Monitoring: Monitor network traffic for anomalous packet patterns directed at the Control Data Access (CDA) service and review system logs for unauthorized execution attempts.

Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the affected Control Data Access components to authorized management workstations only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability, combined with the potential for remote code execution in critical industrial environments, mandates an immediate patching cycle. Organizations should verify their current versions against the affected list provided and prioritize the deployment of the vendor-supplied hotfixes to neutralize this threat.

More Honeywell CVEs

Sources

Originally found and disclosed by Demid Uzenkov and Kirill Kutaev (Positive Technologies), per the CVE Program record.