Background Image
 
Request a Demo
Claroty Toggle Search
Return to Videos
Vulnerabilities Industrial Control Systems (ICS)

Team82 POC Exploit of Honeywell VirtualUOC

Team82 uncovers critical vulnerabilities in Honeywell ControlEdge VirtualUOC controllers allowing full remote compromise.

Claroty Team82 demonstrates its proof-of-concept exploit targeting Honeywell's ControlEdge VirtualUOC controllers.

The vulnerability, CVE-2023-5389 (CVSS v3 score: 9.1), enables an attacker to remotely execute code and completely compromise the controller by exploiting vulnerabilities in the proprietary EpicMo protocol (TCP port 55565) used between Honeywell Experion servers and controllers.

Key technical details include:

  • Vulnerability analysis of CVE-2023-5389 in Honeywell ControlEdge VirtualUOC

  • Exploiting undocumented functions in the proprietary EpicMo protocol (port 55565)

  • Unsanitized file write operations leading to unauthorized remote code execution

  • Remediation steps and official Honeywell security updates

Interested in learning about Claroty's Cybersecurity Solutions?

Claroty
LinkedIn Twitter YouTube Facebook