peter bassill · operator
$ cve CVE-2014-9186 JSON

CVE-2014-9186

9.8
CRITICAL · CVSS 3.0 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code execution. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.65% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-98
On CISA KEVno
Public exploitnone known
Published2019-04-08
Last modified2026-06-17

Affected (1)

VendorProduct
honeywellexperion process knowledge system

References

→ the Explorer  ·  watch your stack  ·  NVD