10
CVSSv3

CVE-2021-38397

Published: 28/10/2022 Updated: 02/11/2022
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an malicious user to remotely execute arbitrary code and cause a denial-of-service condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

honeywell c200_firmware -

honeywell c200e_firmware -

honeywell c300_firmware -

honeywell application_control_environment_firmware -