Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
Los controladores Honeywell Experion PKS C200, C200E, C300 y ACE son vulnerables a una neutralización inadecuada de elementos especiales en la salida, lo que puede permitir a un atacante ejecutar código arbitrario de forma remota y provocar una condición de Denegación de Servicio.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-74
|
| [email protected] | Primary |
en
CWE-74
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| honeywell | c200_firmware | - | <built-in method update of dict object at 0x7763a28fb040> | Operating System |
| honeywell | c200e_firmware | - | <built-in method update of dict object at 0x7763a3fe8440> | Operating System |
| honeywell | c300_firmware | - | <built-in method update of dict object at 0x7763bb374a00> | Operating System |
| honeywell | application_control_environment_firmware | - | <built-in method update of dict object at 0x7763a28fa300> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:honeywell:c200_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:honeywell:c200:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:honeywell:c200e_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:honeywell:c200e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:honeywell:c300_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:honeywell:c300:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:honeywell:application_control_environment_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:honeywell:application_control_environment:-:*:*:*:*:*:*:* |