PT-2021-4327 · Honeywell · Honeywell Experion Pks
Nadav Erez
+1
·
Published
2021-10-06
·
Updated
2022-11-02
·
CVE-2021-38397
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Honeywell Experion PKS versions C200, C200E, C300, and ACE
Description
The issue is related to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition. This could potentially enable an attacker to disrupt the system's operation.
Recommendations
For Honeywell Experion PKS versions C200, C200E, C300, and ACE, consider restricting file uploads to prevent remote execution of arbitrary code until a patch is available.
As a temporary workaround, restrict access to file upload functionality to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Honeywell Experion Pks