Known vulnerabilities in Experion Process Knowledge System C300 and ACE controllers

Software CPE: cpe:2.3:h:honeywell_international:experion_process_knowledge_system_c300_and_ace_controllers:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Experion Process Knowledge System C300 and ACE controllers Experion Process Knowledge System C300 and ACE controllers is affected by 3 known vulnerabilities: 2 high, 1 medium Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU57090 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-38399
CWE-22 Medium
No
No
R510.2 Hotfix10 06.10.2021 SB2021100608
#VU57089 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2021-38395
CWE-74 High
No
No
R510.2 Hotfix10 06.10.2021 SB2021100608
#VU57088 - Unrestricted Upload of File with Dangerous Type
CVE-2021-38397
CWE-434 High
No
No
R510.2 Hotfix10 06.10.2021 SB2021100608