Vulnerabilities > Honeywell > Application Control Environment Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-10-28 CVE-2021-38395 Injection vulnerability in Honeywell products
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
network
low complexity
honeywell CWE-74
critical
9.8
2022-10-28 CVE-2021-38397 Unrestricted Upload of File with Dangerous Type vulnerability in Honeywell products
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
network
low complexity
honeywell CWE-434
critical
10.0
2022-10-28 CVE-2021-38399 Path Traversal vulnerability in Honeywell products
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.
network
low complexity
honeywell CWE-22
7.5