First published: Fri Oct 28 2022(Updated: )
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell C200 | ||
Honeywell C200E | ||
Honeywell C300 and ACE controllers | ||
Honeywell C200 Firmware | ||
Honeywell C200 | ||
Honeywell C200e Firmware | ||
Honeywell C200E | ||
Honeywell C300 Firmware | ||
Honeywell C300 | ||
Honeywell Application Control Environment Firmware | ||
Honeywell Application Control Environment |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-38397.
The severity of CVE-2021-38397 is critical with a severity value of 10.
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are affected by CVE-2021-38397.
CVE-2021-38397 may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
To fix the vulnerability CVE-2021-38397, it is recommended to apply the patches and updates provided by Honeywell.