logo

Exploiting Honeywell ControlEdge VirtualUOC

ID: 6a8b927f-f0af-54c8-836c-21b3eb39e814

STIX ID: report--6a8b927f-f0af-54c8-836c-21b3eb39e814

Feed Name: Claroty Team82

Threat Score
85/100

Date Published: 2024-05-16

Date Updated: 2026-04-17

Author: Uri Katz

...
...

Team82 discovered multiple vulnerabilities in Honeywell ControlEdge Virtual UOC's proprietary EpicMo protocol (TCP/55565) that allow unauthenticated arbitrary file writes and lead to pre-auth remote code execution (CVE-2023-5389). The researchers demonstrated a PoC by uploading and replacing a shared object (/lib/libcap.so.2) to achieve RCE, and Honeywell has issued updates while CISA published advisories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.