logo

Target DCS: Finding, Fixing Critical Bugs in Honeywell Experion PKS

ID: 3f8a8e67-b103-5bc2-84c5-c9f4d99c5730

STIX ID: report--3f8a8e67-b103-5bc2-84c5-c9f4d99c5730

Feed Name: Claroty Team82

Threat Score
80/100

Date Published: 2023-08-27

Date Updated: 2026-04-17

Author: Nadav Erez

...
...

Team82 disclosed three critical vulnerabilities in Honeywell Experion PKS DCS controllers that permit unauthenticated upload and execution of arbitrary Control Component Library (CCL) DLL/ELF files (leading to remote code execution) and relative path traversal; ICS‑CERT rated the issues CVSS 10.0. Honeywell released patches and added cryptographic signing for CCLs, and customers are urged to apply server and firmware updates to mitigate the high-risk flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.