First published: Fri Oct 28 2022(Updated: )
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell C200 Firmware | ||
Honeywell C200e Firmware | ||
Honeywell C300 Controller | ||
Honeywell C200e Firmware | ||
Honeywell C200 Firmware | ||
Honeywell C200e Firmware | ||
Honeywell C200e Firmware | ||
Honeywell C300 Controller | ||
Honeywell C300 Controller | ||
Honeywell Application Control Environment Firmware | ||
Honeywell Application Control Environment Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-38399.
The severity of CVE-2021-38399 is high with a CVSS score of 7.5.
Honeywell Experion PKS C200, C200E, C300, and ACE controllers with specific firmware versions are affected by CVE-2021-38399.
The vulnerability may allow an attacker to access unauthorized files and directories.
To address the vulnerability, it is recommended to follow the mitigation steps provided by Honeywell as mentioned in their notification.