#VU57089 Improper Neutralization of Special Elements in Output Used by a Downstream Component in Honeywell International, Inc products - CVE-2021-38395
Published: October 6, 2021
Experion Process Knowledge System C200
Experion Process Knowledge System C200E
Experion Process Knowledge System C300 and ACE controllers
Honeywell International, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper neutralization of special elements in output. A remote attacker can execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.