Team82 uncovers critical vulnerabilities in Honeywell ControlEdge VirtualUOC controllers allowing full remote compromise.
Claroty Team82 demonstrates its proof-of-concept exploit targeting Honeywell's ControlEdge VirtualUOC controllers.
The vulnerability, CVE-2023-5389 (CVSS v3 score: 9.1), enables an attacker to remotely execute code and completely compromise the controller by exploiting vulnerabilities in the proprietary EpicMo protocol (TCP port 55565) used between Honeywell Experion servers and controllers.
Key technical details include:
Vulnerability analysis of CVE-2023-5389 in Honeywell ControlEdge VirtualUOC
Exploiting undocumented functions in the proprietary EpicMo protocol (port 55565)
Unsanitized file write operations leading to unauthorized remote code execution
Remediation steps and official Honeywell security updates