CVE-2021-38399

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
28/10/2022
Last modified:
02/11/2022

Description

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:honeywell:c200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:c200:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:c200e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:c200e:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:c300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:c300:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:application_control_environment_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:application_control_environment:-:*:*:*:*:*:*:*