Honeywell Experion PKS and OneWireless WDM Control Data Access Component Integer Underflow Vulnerability Allowing Remote Code Execution

Vulnerability

An integer underflow vulnerability has been identified in the Control Data Access (CDA) component of Honeywell Experion PKS and OneWireless WDM. This vulnerability could be exploited to manipulate communication channels, potentially leading to remote code execution. The affected versions of Experion PKS are 520.1 prior to 520.2 TCU9, and 530 prior to 530 TCU3. OneWireless WDM versions 322.1 through 322.4 and 330.1 through 330.3 are also affected.

Impact

Exploitation of this vulnerability could result in unauthorized remote code execution on the affected system.

Remediation

Users are advised to update to the latest versions of Honeywell Experion PKS: 520.2 TCU9 HF1, 530.1 TCU3 HF1, and OneWireless: 322.5 or 331.1.

Added: Jul 10, 2025, 9:36 PM
Updated: Jul 10, 2025, 9:36 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
7.0
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.