CVE-2025-2523 Details
Description
The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in a failure during subtraction allowing remote code execution. Honeywell recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1. The affected Experion PKS products are C300 PCNT02, C300 PCNT05, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are from 520.1 through 520.2 TCU9 and from 530 through 530 TCU3. The OneWireless WDM affected versions are 322.1 through 322.4 and 330.1 through 330.3.
An integer underflow vulnerability has been identified in the Control Data Access (CDA) component of Honeywell Experion PKS and OneWireless WDM. This vulnerability could be exploited to manipulate communication channels, potentially leading to remote code execution. The affected versions of Experion PKS are 520.1 prior to 520.2 TCU9, and 530 prior to 530 TCU3. OneWireless WDM versions 322.1 through 322.4 and 330.1 through 330.3 are also affected.
Users are advised to update to the latest versions of Honeywell Experion PKS: 520.2 TCU9 HF1, 530.1 TCU3 HF1, and OneWireless: 322.5 or 331.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2025CISA-ADP
Assessed Jul 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://process.honeywell.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-191 | Integer Underflow (Wrap or Wraparound) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Honeywell Experion PKS | >= 520.1, <= 520.2 TCU9 >= 530, <= 530 TCU3 |
CPE
Remediation
| |
| Honeywell OneWireless WDM | >= 322.1, <= 322.4 >= 330.1, <= 330.3 |
CPE
Remediation
| |
| Honeywell C300 PCNT02 | All versions |
CPE
Remediation
| |
| Honeywell C300 PCNT05 | All versions |
CPE
Remediation
| |
| Honeywell FIM4 | All versions |
CPE
Remediation
| |
| Honeywell FIM8 | All versions |
CPE
Remediation
| |
| Honeywell UOC | All versions |
CPE
Remediation
| |
| Honeywell CN100 | All versions |
CPE
Remediation
| |
| Honeywell HCA | All versions |
CPE
Remediation
| |
| Honeywell C300PM | All versions |
CPE
Remediation
| |
| Honeywell C200E | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2025 | New CVE Received | [email protected] |
Volerion