Vulnerabilities > Honeywell
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-28 | CVE-2021-38395 | Injection vulnerability in Honeywell products Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition. | 9.8 |
2022-10-28 | CVE-2021-38397 | Unrestricted Upload of File with Dangerous Type vulnerability in Honeywell products Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition. | 10.0 |
2022-10-28 | CVE-2021-38399 | Path Traversal vulnerability in Honeywell products Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories. | 7.5 |
2022-09-16 | CVE-2022-2332 | Incorrect Permission Assignment for Critical Resource vulnerability in Honeywell Softmaster 4.51 A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment. | 7.8 |
2022-09-16 | CVE-2022-2333 | Uncontrolled Search Path Element vulnerability in Honeywell Softmaster 4.51 If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster version 4.51 application’s context and permissions. | 7.8 |
2022-09-07 | CVE-2022-30312 | Cleartext Transmission of Sensitive Information vulnerability in Honeywell products The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. | 6.5 |
2022-08-31 | CVE-2022-30317 | Missing Authentication for Critical Function vulnerability in Honeywell Experion LX Firmware Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. | 9.1 |
2022-08-31 | CVE-2022-30318 | Use of Hard-coded Credentials vulnerability in Honeywell Controledge PLC Firmware and Controledge RTU Firmware Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. | 9.8 |
2022-07-28 | CVE-2022-30313 | Missing Authentication for Critical Function vulnerability in Honeywell Safety Manager Firmware Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. | 7.5 |
2022-07-28 | CVE-2022-30314 | Use of Hard-coded Credentials vulnerability in Honeywell Safety Manager Firmware Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. | 4.6 |