← Back to browse · API

CVE-2021-38397

Severity
CRITICAL
CVSS
10.0
EPSS
0.00912
Risk score
40.32
CISA KEV
No
PoC
No
Published
2022-10-28
Modified
2025-04-16
First seen
2026-08-07
Aliases
EUVD-2021-24849, GHSA-J77H-24P8-J3G2
Products
Honeywell:Experion PKS ACE controllers, Honeywell:Experion PKS C200, Honeywell:Experion PKS C200E, Honeywell:Experion PKS C300
Sources
euvd EUVD-2021-24849

Description

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.

References