Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Honeywell International Inc.

First CVE: May 31, 2007Active for: 19 yearsTotal CVEs: 103
47.4
VTI Score
High

Honeywell International operates a broad portfolio of industrial control systems, process automation platforms, and building-management solutions deployed across critical infrastructure and manufacturing environments, presenting a substantial attack surface where security flaws can have operational consequences. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes across flagship products such as the Saia PG5 Controls Suite, C300 controllers, and Experion Process Knowledge System, reflecting the complexity and privileged nature of automation and control logic. The exposure recurs through weakness classes including path traversal, out-of-bounds writes, missing authentication for critical functions, XML external entity injection, and improper input validation—attack patterns endemic to industrial software that often prioritizes functional integration and backward compatibility over input sanitization and access controls. Defenders managing Honeywell-based infrastructure should treat severity advisories as high-priority and assess network segmentation and authentication hardening around these systems; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
103
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Honeywell International Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 31, 2007
19 years ago
Most Recent CVE
Mar 12, 2026
134 days ago

Self-Reporting Analysis

Of all the CVEs published by Honeywell International Inc. as a CNA, 37.9% affect products that Honeywell International Inc. develops as a vendor.

37.9%
62.1%
Self-reported: 22 (37.9%)
Third-party: 36 (62.1%)

Of all the CVEs published that affect products developed by Honeywell International Inc., 21.4% are self-published by Honeywell International Inc. as a CNA.

21.4%
78.6%
Self-published: 22 (21.4%)
Other CNAs: 81 (78.6%)

Products(387 total)

Top CVEs

Signals from CVEs in this vendor scope (103 CVEs).

103 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-3710CRITICAL
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004
Sep 12, 20239.868NOYES
CVE-2007-2938HIGH
Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to
May 31, 200710.060NOYES
CVE-2013-0108MEDIUM
An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open
Feb 24, 20136.858NOYES
CVE-2026-3611CRITICAL
The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, secur
Mar 12, 202610.036NONO
CVE-2025-2605HIGH
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure
May 2, 20258.833NONO
CVE-2021-38397CRITICAL
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause
Oct 28, 202210.032NONO
CVE-2022-30318CRITICAL
Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components
Aug 31, 20229.832NONO
CVE-2014-5435CRITICAL
An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lea
Apr 8, 20199.832NONO
CVE-2021-38395CRITICAL
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execu
Oct 28, 20229.831NONO
CVE-2021-39363CRITICAL
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.
Feb 24, 20229.831NONO
View all 103 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products103 CVEs
25%
49%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (7.8%)
Network77 (74.8%)
Unknown11 (10.7%)
Physical3 (2.9%)
Adjacent Network4 (3.9%)
Attack Complexity
Low89 (86.4%)
High3 (2.9%)
Unknown11 (10.7%)
User Interaction
None76 (73.8%)
Unknown11 (10.7%)
Required16 (15.5%)
Privileges Required
Low15 (14.6%)
High2 (1.9%)
None75 (72.8%)
Unknown11 (10.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (103 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.0% of CVEs· 97th percentile
Nuclei
1 CVE
1.0% of CVEs· 95th percentile
ExploitDB
5 CVEs
4.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Honeywell International Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Honeywell International Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Honeywell International Inc.'s Products

View all 6 CNAs →

Top CWEs