CVE-2022-30315: Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity
criticalvulnerability
security
Summary
Honeywell Experion PKS Safety Manager controllers have a vulnerability where control logic downloaded to the device is not cryptographically authenticated (meaning the system doesn't verify the logic came from a trusted source). This allows an attacker who can communicate with the controller to run arbitrary machine code on it, potentially taking control of safety systems similar to how the TRITON malware (a real-world attack on industrial control systems) operated.
Vulnerability Details
CVSS Score
9.8(critical)
EPSS (30-day exploit probability)
EPSS: 1.4%
Classification
Attack SophisticationModerate
Taxonomy References
CWE (Weakness Type)
Original source: https://nvd.nist.gov/vuln/detail/CVE-2022-30315
First tracked: February 15, 2026 at 08:45 PM
Classified by LLM (prompt v3) · confidence: 95%