First published: Fri Oct 28 2022(Updated: )
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell C200 | ||
Honeywell C200E | ||
Honeywell C300 and ACE controllers | ||
Honeywell C200 Firmware | ||
Honeywell C200 | ||
Honeywell C200e Firmware | ||
Honeywell C200E | ||
Honeywell C300 Firmware | ||
Honeywell C300 | ||
Honeywell Application Control Environment Firmware | ||
Honeywell Application Control Environment |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-38399.
The severity of CVE-2021-38399 is high with a CVSS score of 7.5.
Honeywell Experion PKS C200, C200E, C300, and ACE controllers with specific firmware versions are affected by CVE-2021-38399.
The vulnerability may allow an attacker to access unauthorized files and directories.
To address the vulnerability, it is recommended to follow the mitigation steps provided by Honeywell as mentioned in their notification.