Security vulnerabilities in Honeywell devices could be used to disrupt critical industries.
Security researchers discovered numerous vulnerabilities in Honeywell devices used in critical industries, which, if exploited, could allow a hacker to cause physical disruption and potentially affect the safety of human lives.
See also: USB drive malware attacks increased in the first half of 2023

Researchers at Armis, a cybersecurity firm specializing in asset security, have uncovered nine vulnerabilities in Honeywell’s Experion distributed control system (DCS) products. These are digitally automated industrial control systems used to control large industrial processes in mission-critical industries—such as energy and pharmaceuticals—where high availability and continuous operation are critical.
See also: 20% of malware attacks bypass antivirus protection
The vulnerabilities — seven of which are rated critical — could allow an attacker to remotely execute unauthorized code on both Honeywell’s server and controllers, according to Armis. An attacker would need network access to exploit the vulnerabilities, which could be gained by compromising a device within a network, from a laptop to a vending machine. However, the flaws allow unauthenticated access, meaning an attacker wouldn’t have to log in to the controller to exploit.
While there is no evidence of active exploitation, Armis told TechCrunch that hackers could use these vulnerabilities to take over devices and modify the operation of the DCS controller.
This is particularly problematic for the oil and gas extraction industry, Armis says—that’s where Honeywell’s DCS systems operate. According to Honeywell’s website, its customers include energy giant Shell , U.S. government agencies such as the Department of Defense and NASA , and research-based biopharmaceutical company AstraZeneca

See also: New attack drops LokiBot Malware via malicious Macros in Word Docs
Armis told TechCrunch that it notified Honeywell of the vulnerabilities, which affected a number of its DCS platforms, including Honeywell Experion Process Knowledge System, LX and PlantCruise and the C300 DCS Controller, in May. Honeywell released patches the following month and is urging all affected organizations to implement immediately.
Information source: techcrunch.com
