CVE-2025-3947
8.2Honeywell · Experion PKS
Honeywell Experion PKS contains an integer underflow vulnerability in the Control Data Access component, which could allow an unauthenticated attacker to cause a denial of service.
Executive summary
An integer underflow vulnerability in Honeywell Experion PKS allows unauthenticated remote attackers to trigger a denial of service via input data manipulation.
Vulnerability
This vulnerability is an integer underflow (CWE-191) residing in the Control Data Access component. The flaw permits an unauthenticated attacker to manipulate input data, causing improper integer value checking during subtraction and resulting in a denial of service.
Business impact
The vulnerability carries a CVSS score of 8.2, reflecting a high severity due to its potential to disrupt critical industrial control processes. A successful exploit leads to a denial of service, which can cause significant operational downtime, loss of process control, and potential safety risks in industrial environments.
Remediation
Immediate Action: Update the affected Honeywell Experion PKS components to version 520.2 TCU9 HF1 or 530.1 TCU3 HF1 immediately.
Proactive Monitoring: Monitor Control Data Access logs for anomalous traffic patterns or sudden service interruptions that may indicate attempts to trigger the underflow condition.
Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the Control Data Access component to authorized internal systems only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of the Honeywell Experion PKS in industrial environments, this vulnerability poses a severe risk to availability. Administrators must prioritize the application of the provided hotfixes, 520.2 TCU9 HF1 or 530.1 TCU3 HF1, to eliminate the risk of service disruption. Until updates can be deployed, ensure that network perimeter defenses are configured to prevent unauthorized access to the Control Data Access service.
More Honeywell CVEs
Sources
Originally found and disclosed by Demid Uzenkov and Kirill Kutaev (Positive Technologies), per the CVE Program record.