CVE-2021-38397 is a critical vulnerability affecting Honeywell Experion PKS C200, C200E, C300, and ACE controllers, allowing unrestricted file uploads. This flaw enables an unauthenticated attacker to remotely execute arbitrary code and cause a denial-of-service condition. With a CVSS score of 10.0 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No), the vulnerability has garnered significant community attention with 11 mentions and a dedicated NASL script on GitHub, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:honeywell:c200_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:honeywell:c200e_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:honeywell:c300_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:honeywell:application_control_environment_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.