Critical severity10.0NVD Advisory· Published Oct 28, 2022· Updated Jun 17, 2026
CVE-2021-38397
CVE-2021-38397
Description
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:o:honeywell:application_control_environment_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:honeywell:c200_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:honeywell:c200e_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:honeywell:c300_firmware:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.cisa.gov/uscert/ics/advisories/icsa-21-278-04nvdThird Party AdvisoryUS Government Resource
- www.honeywellprocess.com/library/support/notifications/Customer/SN2021-02-22-01-Experion-C300-CCL.pdfnvdProduct
News mentions
0No linked articles in our index yet.