PT-2021-4325 · Honeywell · Honeywell Experion Pks
Published
2021-10-06
·
Updated
2022-11-02
·
CVE-2021-38399
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Honeywell Experion PKS versions C200, C200E, C300, and ACE controllers
Description
The issue is related to insufficient restrictions on directory path names in the operating system of Honeywell's industrial portable computers. This can be exploited by a remote attacker to perform cross-site scripting attacks, potentially allowing access to unauthorized files and directories.
Recommendations
For Honeywell Experion PKS C200, C200E, C300, and ACE controllers, consider restricting access to sensitive directories and files as a temporary mitigation measure until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Honeywell Experion Pks