CVE-2021-38397

CRITICAL

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-servi...

Affects 8 products across 1 vendor.

BCS7.68
CVSS 3.110.0
EPSS0.9%
Percentile56th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-434

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are affected by a critical vulnerability (CVE-2021-38397) that allows unrestricted file uploads, potentially leading to remote code execution and denial-of-service conditions. The CVSS score is 10.0, indicating a severe risk. Immediate action is required to mitigate this vulnerability due to its potential impact on safety and operational continuity in industrial control systems.

BSID: BS-2022-GLOBAL-304940-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-38397?
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are affected by a critical vulnerability (CVE-2021-38397) that allows unrestricted file uploads, potentially leading to remote code execution and denial-of-service conditions. The CVSS score is 10.0, indicating a severe risk. Immediate action is required to mitigate this vulnerability due to its potential impact on safety and operational continuity in industrial control systems.
What is the CVSS score for CVE-2021-38397?
CVE-2021-38397 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.9%.
Is CVE-2021-38397 actively exploited?
No confirmed active exploitation of CVE-2021-38397 as of 2026-05-30.
How do I remediate CVE-2021-38397?
Priority: IMMEDIATE. Advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-21-278-04
What systems are affected by CVE-2021-38397?
CVE-2021-38397 affects: Honeywell, Honeywell, Honeywell, Honeywell, Honeywell, Honeywell, Honeywell, Honeywell.
What NERC-CIP standard applies to CVE-2021-38397?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to the control system, which can lead to the execution of malicious code and compromise the security of the electronic security perimeter.
What IEC 62443 requirement maps to CVE-2021-38397?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability in the file upload mechanism, which can be exploited to execute arbitrary code and disrupt the operation of the control system, violating the principle of secure software development and deployment.
Vulnerability Details
CVE IDCVE-2021-38397
BSIDBS-2022-GLOBAL-304940-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2022-10-28
Last Modified2024-11-21
ICS Relevance85%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the file upload functionality of the Honeywell Experion PKS controllers. An attacker can exploit this vulnerability over the network without authentication, leading to the execution of arbitrary code and causing a denial-of-service condition. This could result in loss of control, data corruption, and system downtime, posing significant risks to safety and operational integrity.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Honeywell C200 Firmware
Honeywell C200
Honeywell C200E Firmware
Honeywell C200E
Honeywell C300 Firmware
Honeywell C300
Honeywell Application Control Environment Firmware
Honeywell Application Control Environment
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 1378 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict file upload restrictions and validate all incoming files to prevent unauthorized uploads. Use network segmentation and access controls to limit exposure to untrusted networks.

SURICATA RULE
alert tcp any any -> any any (msg:"Honeywell Experion PKS Unrestricted File Upload Attempt"; content:"POST /upload"; http_method; content:"Content-Type: multipart/form-data"; http_header; sid:9100285; rev:1;)
NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to the control system, which can lead to the execution of malicious code and compromise the security of the electronic security perimeter.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability in the file upload mechanism, which can be exploited to execute arbitrary code and disrupt the operation of the control system, violating the principle of secure software development and deployment.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash31ceb158e7b3d4c30917641637c97acb4b3a96397d43689c2634dcc47c8a25dc1210ea0e58bcff5d100ead0c6eacfb71ccc8dd21450ff4d4583e42b1e84b6e5c
Related CVEs affecting Honeywell
CVE-2026-3611 10.0 The Honeywell IQ4x building management controller, exposes its full web-based... CVE-2022-31481 10.0 An unauthenticated attacker can send a specially crafted update file to the d... CVE-2007-2938 10.0 Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader... CVE-2015-0984 10.0 Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL... CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2...
View all Honeywell CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →