CVE-2021-38397: Honeywell Experion PKS and ACE Controllers Unrestricted Upload of File with Dangerous Type
Published Oct 28, 2022
·Updated
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
Affected Software
11 affected components
Honeywell C200
Honeywell C200E
Honeywell C300 and ACE controllers
Honeywell C200 Firmware
Honeywell C200
Honeywell C200e Firmware
Honeywell C200E
Honeywell C300 Firmware
Honeywell C300
Honeywell Application Control Environment Firmware
Honeywell Application Control Environment
Event History
Oct 28, 2022
CVE Published
via MITRE·01:21 AM
Data Sourced
via MITRE·01:21 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38397.
2
What is the severity of CVE-2021-38397?
The severity of CVE-2021-38397 is critical with a severity value of 10.
3
Which Honeywell controllers are affected by CVE-2021-38397?
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are affected by CVE-2021-38397.
4
What is the impact of CVE-2021-38397?
CVE-2021-38397 may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
5
How can I fix the vulnerability CVE-2021-38397?
To fix the vulnerability CVE-2021-38397, it is recommended to apply the patches and updates provided by Honeywell.