First published: Fri Oct 28 2022(Updated: )
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell C200 | ||
Honeywell C200E | ||
Honeywell C300 and ACE controllers | ||
Honeywell C200 Firmware | ||
Honeywell C200 | ||
Honeywell C200e Firmware | ||
Honeywell C200E | ||
Honeywell C300 Firmware | ||
Honeywell C300 | ||
Honeywell Application Control Environment Firmware | ||
Honeywell Application Control Environment |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38395 is a vulnerability found in Honeywell Experion PKS C200, C200E, C300, and ACE controllers, which allows remote execution of arbitrary code and can cause a denial-of-service condition.
CVE-2021-38395 is considered a critical vulnerability with a severity score of 9.8 out of 10.
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are affected by CVE-2021-38395.
An attacker can exploit CVE-2021-38395 by sending specially crafted input to the affected controllers, allowing them to execute arbitrary code remotely.
Yes, it is recommended to apply the necessary patches or updates provided by Honeywell to mitigate CVE-2021-38395.