← Back to home
ICSA-22-256-02  ·  Published 2022-09-13  ·  View on CISA ICS-CERT ↗

Honeywell SoftMaster

CVSS 8.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to execute code in the context of the application permissions or escalate privileges.

Remediations

  • Honeywell has released firmware update packages for the affected products on their website. Honeywell recommends users with potentially affected products take the following steps to protect themselves:
  • Update firmware of vulnerable and affected devices.
  • Isolate systems from the internet or create additional layers of defense to their system from the internet by placing the affected hardware behind a firewall or into a demilitarized zone (DMZ).
  • If remote connections to the network are required, then users should consider using a VPN or other means to ensure secure remote connections into the network where the device is located.

Affected Vendors

Honeywell

Affected Products (1)

Honeywell · SoftMaster 4.51

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more