60
CVE-2021-38397
—CVSS 3.1
10.0 critical
EPSS
<1%p59
Published
()
Modified
Description
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
- Vendors
- honeywell
- Products
- c200 firmware, c200e firmware, c300 firmware, application control environment firmware
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H