Operational Advisory Overview

Honeywell Process Solutions and the Cybersecurity and Infrastructure Security Agency (CISA) have released security notification SN2026-04 regarding a critical Denial-of-Service flaw designated CVE-2026-64890 (CVSS v3.1 8.6) in the Experion PKS C300 Controller. An unauthenticated attacker on the local supervisory network can transmit malformed Fault Tolerant Ethernet (FTE) control frames, crashing both primary and secondary redundant controllers simultaneously.

Protocol Analysis & System Behavior

Honeywell Experion PKS C300 controllers operate as the central process execution engine across oil refineries, petrochemical processing plants, mining smelters, and power utilities worldwide. C300 controllers deploy redundant controller pairs connected through Honeywell's proprietary Fault Tolerant Ethernet (FTE) network, which delivers multi-path redundancy over dual network interface cards.

The vulnerability exists within the FTE network driver's packet reassembly module on UDP port 5150. When processing fragmented multicast diagnostic beacons, the embedded driver fails to handle out-of-order segment offsets properly:

Experion Architecture:
[Honeywell Experion Server / Console Station]
                  |  (Supervisory FTE Network)
[FTE Switch Infrastructure (Yellow / Green Cable Trunks)]
                  |  (UDP Port 5150 Fragmented Frame Injection)
[Honeywell C300 Controller Pair (Primary & Secondary)]
                  |  (Kernel Exception & Simultaneous Watchdog Trip)
[Process Loops Freeze: Control Output Modules Maintain Last Value (MLV)]

Because both the active primary C300 and the hot-standby secondary C300 process identical FTE multicast frames simultaneously, the malformed payload triggers an unhandled memory exception in both execution cores at the exact same instant, causing dual-controller failure.

Industrial Consequence Matrix

When dual C300 controllers crash, the system enters an uncommanded fail-safe state where analog output modules lock at their last-known value (Maintain Last Value - MLV) or transition to pre-configured de-energized states. This can cause:

  • Loss of view and loss of control on operator Human-Machine Interface (HMI) screens.
  • Thermal runaway in exothermic chemical reactors if cooling water valve setpoints cannot be adjusted.
  • Emergency flaring and plant trip initiation, resulting in extensive product waste and environmental burnoff.

Mitigation & Defense Recommendations

Honeywell has released hotfix patches for all supported Experion PKS releases. Industrial asset owners must implement the following safeguards:

  1. Patch Installation: Apply Honeywell Security Notification SN2026-04 across all affected C300 controller nodes during scheduled maintenance turnarounds.
  2. FTE Port Filtering: Configure industrial access control lists (ACLs) on managed switches to drop all external UDP 5150 traffic from non-Honeywell device MAC addresses.
  3. Zone Boundary Segmentation: Enforce strict IEC 62443-3-2 zone segmentation ensuring FTE control networks are inaccessible from corporate IT networks.