Back

CVE-2014-5435

CRITICAL

An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

Published: Apr 8, 2019 Modified: Jun 17, 2026
CWE-123 CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
honeywell experion_process_knowledge_system * ≥ r400 < r400.6
honeywell experion_process_knowledge_system * ≥ r410 < r410.6
honeywell experion_process_knowledge_system * ≥ r430 < r430.2

GitHub Security Advisory GHSA-3gh5-wq3g-32vj

An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion...

References (2)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.47%

Top 12% most likely to be exploited

Threat Score 40.2 / 100

Data Sources

NVD EPSS GitHub