Back

CVE-2014-9186

CRITICAL

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code execution. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

Published: Apr 8, 2019 Modified: Jun 17, 2026
CWE-98 CWE-20

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
honeywell experion_process_knowledge_system * ≥ r400 < r400.6
honeywell experion_process_knowledge_system * ≥ r410 < r410.6
honeywell experion_process_knowledge_system * ≥ r430 < r430.2

GitHub Security Advisory GHSA-7q7j-2f25-p5hw

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x...

References (2)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.65%

Top 11% most likely to be exploited

Threat Score 40.3 / 100

Data Sources

NVD EPSS GitHub