Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Claroty Team82 reported that CVE-2023-5389 can let an unauthenticated attacker write files to a Honeywell ControlEdge Virtual UOC controller and achieve remote code execution. The attacker must first be able to reach the controller from the organization’s operational technology (OT) network; the finding does not establish that a controller exposed to the public internet is required or that internet users can necessarily reach the vulnerable service.

What is affected

The issue is in the EpicMo protocol implementation in Honeywell ControlEdge Virtual UOC. Honeywell’s Unit Operations Controller extends the Experion control environment. Virtual UOC is a Linux-based virtual machine that can be deployed in a virtual environment instead of using a physical controller. Claroty identifies TCP port 55565 as the port used by EpicMo, a proprietary protocol for communications between Honeywell Experion servers and controllers. Claroty Team82’s disclosure describes the vulnerability and protocol.

How CVE-2023-5389 can lead to remote code execution

Claroty describes an undocumented file-writing function that did not sanitize file paths or content. An attacker who can reach the controller over the OT network can invoke the function without authenticating to the controller. Claroty demonstrated that modifying files through this capability could lead to code execution on the virtual controller.

“Remote” describes execution across the network, not unrestricted access from anywhere: the attacker’s ability to reach the vulnerable service is a precondition. Claroty’s finding does not, by itself, establish public-internet exposure or report observed attacks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How CVE-2023-5389 differs from CVE-2023-5390

The two CVEs describe distinct issues in the EpicMo-related findings. CVE-2023-5389 is the file-writing flaw associated with code execution. CVE-2023-5390 is an absolute path-traversal issue that can allow files to be read; it is not the RCE flaw.

CVE Reported issue and impact Severity score and source
CVE-2023-5389 Unauthenticated file writing that Claroty says can lead to remote code execution on ControlEdge Virtual UOC; the attacker must be able to reach the controller over the OT network. CVSS v3 9.1, reported by Claroty Team82 in 2024.
CVE-2023-5390 Absolute path traversal and file reading affecting Experion ControlEdge VirtualUOC and ControlEdge UOC, potentially exposing limited device information, according to the Honeywell-sourced NVD description. CVSS v3 5.3, reported by Claroty Team82 in 2024. NVD rates it 5.3 Medium under CVSS 3.1; its listed vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N.

The NVD record for CVE-2023-5390 is sourced to Honeywell International Inc. and was last modified November 21, 2024. A CVSS score rates vulnerability severity; it does not establish how likely exploitation is or whether attacks have been observed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What operators should do

Claroty reports that Honeywell updated Virtual UOC and advises users to move to current versions. The Honeywell-sourced NVD description for CVE-2023-5390 likewise recommends updating to the latest product version. The public information cited here does not establish an exact fixed release number, so do not assume a particular version is safe based on an unverified number.

  • Identify whether your site runs ControlEdge Virtual UOC or ControlEdge UOC and determine the deployed version.
  • Contact Honeywell support for the security notification, applicable fixed version, and upgrade or change guidance for that deployment.
  • Plan and apply the vendor-recommended update through your site’s OT change-management process.

For product context, see Honeywell’s ControlEdge controllers page. Claroty links to CISA advisory ICSA-24-116-04, but details of that advisory are not included here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Electrical Motor Controls for Integrated Systems
  • A trusted resource for students, technicians, and professionals seeking to advance their skills in motor controls, integrated systems, and industrial automation across manufacturing and technical trade programs
  • Available in multiple formats including printed textbook, eTextbook (lifetime or 180-day access), and a Premium Access Package combining both print and digital versions for flexible learning
  • Written by Gary J. Rockis and Glen A. Mazur, experienced authors and educators in electrical and industrial technology, published by ATP Learning (American Technical Publishers)
  • Accompanied by an Applications Manual with hands-on activities that expand on textbook content — can be used as a stand-alone training tool or alongside the main textbook
  • Covers a comprehensive range of topics including electrical, motor, and mechanical devices and their application in industrial control circuits, making it ideal for both students and working professionals

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.