← back
CVE-2021-38395criticalCWE-74

Honeywell Experion PKS and ACE Controllers Injection

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.1epss 0.9%
exploitation probability
0.9%top 45% of all CVEs
observed exploitation
nono source reports it
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected products
Honeywell · Experion PKS