Vulnerability Details CVE-2021-38397
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.1%
CVSS Severity
CVSS v3 Score 10.0
Products affected by CVE-2021-38397
-
cpe:2.3:h:honeywell:application_control_environment:-
-
cpe:2.3:h:honeywell:c200:-
-
cpe:2.3:h:honeywell:c200e:-
-
cpe:2.3:h:honeywell:c300:-
-
cpe:2.3:o:honeywell:application_control_environment_firmware:-
-
cpe:2.3:o:honeywell:c200_firmware:-
-
cpe:2.3:o:honeywell:c200e_firmware:-
-
cpe:2.3:o:honeywell:c300_firmware:-