CVE-2025-2522
Severity CVSS v4.0:
Pending analysis
Type:
CWE-226
Sensitive Information in Resource Not Removed Before Reuse
Publication date:
10/07/2025
Last modified:
10/07/2025
Description
The Honeywell Experion PKS and OneWireless WDM <br />
<br />
contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect system behavior.<br />
<br />
Honeywell also recommends updating to the most recent version of <br />
<br />
Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1. <br />
<br />
The affected Experion PKS products are <br />
<br />
<br />
<br />
C300, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are 520.1 before <br />
<br />
520.2 TCU9 HF1 and 530 before 530 TCU3. The OneWireless WDM affected versions are 322.1 through 322.4 and 330.1 through 330.3.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM