CVE-2021-38395
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.94%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- honeywell/c200 firmware · honeywell/c200e firmware · honeywell/c300 firmware · honeywell/application control environment firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-278-04Mitigation, Third Party Advisory, US Government Resource
- https://www.honeywellprocess.com/library/support/notifications/Customer/SN2021-02-22-01-Experion-C300-CCL.pdfProduct
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-278-04Mitigation, Third Party Advisory, US Government Resource
- https://www.honeywellprocess.com/library/support/notifications/Customer/SN2021-02-22-01-Experion-C300-CCL.pdfProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.