PT-2021-4325 · Honeywell · Honeywell Experion Pks

Published

2021-10-06

·

Updated

2022-11-02

·

CVE-2021-38399

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Honeywell Experion PKS versions C200, C200E, C300, and ACE controllers
Description The issue is related to insufficient restrictions on directory path names in the operating system of Honeywell's industrial portable computers. This can be exploited by a remote attacker to perform cross-site scripting attacks, potentially allowing access to unauthorized files and directories.
Recommendations For Honeywell Experion PKS C200, C200E, C300, and ACE controllers, consider restricting access to sensitive directories and files as a temporary mitigation measure until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Relative Path Traversal

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2021-04949
CVE-2021-38399

Affected Products

Honeywell Experion Pks