Honeywell International operates a broad portfolio of industrial control systems, process automation platforms, and building-management solutions deployed across critical infrastructure and manufacturing environments, presenting a substantial attack surface where security flaws can have operational consequences. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes across flagship products such as the Saia PG5 Controls Suite, C300 controllers, and Experion Process Knowledge System, reflecting the complexity and privileged nature of automation and control logic. The exposure recurs through weakness classes including path traversal, out-of-bounds writes, missing authentication for critical functions, XML external entity injection, and improper input validation—attack patterns endemic to industrial software that often prioritizes functional integration and backward compatibility over input sanitization and access controls. Defenders managing Honeywell-based infrastructure should treat severity advisories as high-priority and assess network segmentation and authentication hardening around these systems; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Honeywell International Inc. over time
Of all the CVEs published by Honeywell International Inc. as a CNA, 37.9% affect products that Honeywell International Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Honeywell International Inc., 21.4% are self-published by Honeywell International Inc. as a CNA.
Signals from CVEs in this vendor scope (103 CVEs).
103 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3710CRITICAL Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004 | Sep 12, 2023 | 9.8 | 68 | NO | YES |
CVE-2007-2938HIGH Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to | May 31, 2007 | 10.0 | 60 | NO | YES |
CVE-2013-0108MEDIUM An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open | Feb 24, 2013 | 6.8 | 58 | NO | YES |
CVE-2026-3611CRITICAL The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, secur | Mar 12, 2026 | 10.0 | 36 | NO | NO |
CVE-2025-2605HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure | May 2, 2025 | 8.8 | 33 | NO | NO |
CVE-2021-38397CRITICAL Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause | Oct 28, 2022 | 10.0 | 32 | NO | NO |
CVE-2022-30318CRITICAL Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components | Aug 31, 2022 | 9.8 | 32 | NO | NO |
CVE-2014-5435CRITICAL An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lea | Apr 8, 2019 | 9.8 | 32 | NO | NO |
CVE-2021-38395CRITICAL Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execu | Oct 28, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-39363CRITICAL Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved. | Feb 24, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (103 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Honeywell International Inc..
Media articles that mention a CVE ID that affects a product developed by Honeywell International Inc. — matched by CVE ID, not by vendor name.