Honeywell Alert
2491Warning Date
Severity Level
Warning Number
Target Sector
6 October, 2021
● Critical
2021-3629
Manufacturing
Description:
Honeywell has released a security alert to address several vulnerabilities in the following product:
- Experion PKS
- C200: All versions
- C200E: All versions
- C300 and ACE controllers: All versions
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Execute arbitrary code -remotely
Best practice and Recommendations:
The CERT team encourages users to apply best practice:
- Minimizing network exposure for all control system devices and/or systems
- Locating control system networks and devices behind firewalls and isolating them from the enterprise/business network
- When remote access is required, use secure methods such as virtual private networks (VPNs)
- https://www.honeywellprocess.com/library/support/notifications/Customer/SN2021-02-22-01-Experion-C300-CCL.pdf