PT-2021-4327 · Honeywell · Honeywell Experion Pks

Nadav Erez

+1

·

Published

2021-10-06

·

Updated

2022-11-02

·

CVE-2021-38397

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Honeywell Experion PKS versions C200, C200E, C300, and ACE
Description The issue is related to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition. This could potentially enable an attacker to disrupt the system's operation.
Recommendations For Honeywell Experion PKS versions C200, C200E, C300, and ACE, consider restricting file uploads to prevent remote execution of arbitrary code until a patch is available. As a temporary workaround, restrict access to file upload functionality to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2021-04951
CVE-2021-38397

Affected Products

Honeywell Experion Pks