ZeroHour

CVE-2021-38397

CVSS 3.1
10.0 critical
EPSS
<1%p59
Published
()
Modified
Description

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.

Vendors
honeywell
Products
c200 firmware, c200e firmware, c300 firmware, application control environment firmware
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news