Target DCS: Finding, Fixing Critical Bugs in Honeywell Experion PKS
ID: 3f8a8e67-b103-5bc2-84c5-c9f4d99c5730
STIX ID: report--3f8a8e67-b103-5bc2-84c5-c9f4d99c5730
Feed Name: Claroty Team82
Threat Score
Team82 disclosed three critical vulnerabilities in Honeywell Experion PKS DCS controllers that permit unauthenticated upload and execution of arbitrary Control Component Library (CCL) DLL/ELF files (leading to remote code execution) and relative path traversal; ICS‑CERT rated the issues CVSS 10.0. Honeywell released patches and added cryptographic signing for CCLs, and customers are urged to apply server and firmware updates to mitigate the high-risk flaws.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
