Lucene search

K
cveIcscertCVE-2021-38399
HistoryOct 28, 2022 - 2:15 a.m.

CVE-2021-38399

2022-10-2802:15:17
CWE-23
CWE-22
icscert
web.nvd.nist.gov
49
2
honeywell
experion pks
controllers
vulnerability
path traversal
nvd
cve-2021-38399

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

52.3%

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.

Affected configurations

Nvd
Node
honeywellc200_firmwareMatch-
AND
honeywellc200Match-
Node
honeywellc200e_firmwareMatch-
AND
honeywellc200eMatch-
Node
honeywellc300Match-
AND
honeywellc300_firmwareMatch-
Node
honeywellapplication_control_environmentMatch-
AND
honeywellapplication_control_environment_firmwareMatch-
VendorProductVersionCPE
honeywellc200_firmware-cpe:2.3:o:honeywell:c200_firmware:-:*:*:*:*:*:*:*
honeywellc200-cpe:2.3:h:honeywell:c200:-:*:*:*:*:*:*:*
honeywellc200e_firmware-cpe:2.3:o:honeywell:c200e_firmware:-:*:*:*:*:*:*:*
honeywellc200e-cpe:2.3:h:honeywell:c200e:-:*:*:*:*:*:*:*
honeywellc300-cpe:2.3:h:honeywell:c300:-:*:*:*:*:*:*:*
honeywellc300_firmware-cpe:2.3:o:honeywell:c300_firmware:-:*:*:*:*:*:*:*
honeywellapplication_control_environment-cpe:2.3:h:honeywell:application_control_environment:-:*:*:*:*:*:*:*
honeywellapplication_control_environment_firmware-cpe:2.3:o:honeywell:application_control_environment_firmware:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Honeywell",
    "product": "Experion PKS",
    "versions": [
      {
        "version": "C200",
        "status": "affected"
      },
      {
        "version": "C200E",
        "status": "affected"
      },
      {
        "version": "C300",
        "status": "affected"
      },
      {
        "version": "ACE controllers",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

52.3%

Related for CVE-2021-38399