Honeywell Experion PKS and ACE Controllers Unrestricted Upload of File with Dangerous Type
CVE-2021-38397
10CRITICAL
What is CVE-2021-38397?
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
Affected Version(s)
Experion PKS C200
Experion PKS C200E
Experion PKS C300
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rei Henigman and Nadav Erez of Claroty reported these vulnerabilities to CISA.