CVE-2021-38395 is a critical vulnerability affecting Honeywell Experion PKS C200, C200E, C300, and ACE controllers, stemming from improper neutralization of special elements in output. This allows an unauthenticated remote attacker to execute arbitrary code and cause a denial-of-service condition, as indicated by its CVSS score of 9.8 (CRITICAL). While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed in CISA's KEV catalog, there is notable community discussion and media coverage, suggesting awareness of its potential impact on industrial processes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:honeywell:c200_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:honeywell:c200e_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:honeywell:c300_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:honeywell:application_control_environment_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.