Vulnerabilities > Honeywell

DATE CVE VULNERABILITY TITLE RISK
2022-10-28 CVE-2021-38395 Injection vulnerability in Honeywell products
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
network
low complexity
honeywell CWE-74
critical
9.8
2022-10-28 CVE-2021-38397 Unrestricted Upload of File with Dangerous Type vulnerability in Honeywell products
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
network
low complexity
honeywell CWE-434
critical
10.0
2022-10-28 CVE-2021-38399 Path Traversal vulnerability in Honeywell products
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.
network
low complexity
honeywell CWE-22
7.5
2022-09-16 CVE-2022-2332 Incorrect Permission Assignment for Critical Resource vulnerability in Honeywell Softmaster 4.51
A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment.
local
low complexity
honeywell CWE-732
7.8
2022-09-16 CVE-2022-2333 Uncontrolled Search Path Element vulnerability in Honeywell Softmaster 4.51
If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster version 4.51 application’s context and permissions.
local
low complexity
honeywell CWE-427
7.8
2022-09-07 CVE-2022-30312 Cleartext Transmission of Sensitive Information vulnerability in Honeywell products
The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information.
low complexity
honeywell CWE-319
6.5
2022-08-31 CVE-2022-30317 Missing Authentication for Critical Function vulnerability in Honeywell Experion LX Firmware
Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function.
network
low complexity
honeywell CWE-306
critical
9.1
2022-08-31 CVE-2022-30318 Use of Hard-coded Credentials vulnerability in Honeywell Controledge PLC Firmware and Controledge RTU Firmware
Honeywell ControlEdge through R151.1 uses Hard-coded Credentials.
network
low complexity
honeywell CWE-798
critical
9.8
2022-07-28 CVE-2022-30313 Missing Authentication for Critical Function vulnerability in Honeywell Safety Manager Firmware
Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function.
network
low complexity
honeywell CWE-306
7.5
2022-07-28 CVE-2022-30314 Use of Hard-coded Credentials vulnerability in Honeywell Safety Manager Firmware
Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials.
low complexity
honeywell CWE-798
4.6