7.8
CVE-2021-27477
- EPSS 0.23%
- Veröffentlicht 01.07.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:04
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a receive buffer for FL-net are overwritten. As a result, the PLC CPU detects a system error, and the affected products stop.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jtekt ≫ Pc10g-cpu Firmware Version < 3.91
Jtekt ≫ 2port-efr Firmware Version < 1.50
Jtekt ≫ Plus Cpu Firmware Version < 3.11
Jtekt ≫ Plus Ex Firmware Version < 3.11
Jtekt ≫ Plus Ex2 Firmware Version < 3.11
Jtekt ≫ Plus Efr Firmware Version < 3.11
Jtekt ≫ Plus Efr2 Firmware Version < 3.11
Jtekt ≫ Plus 2p-efr Firmware Version < 3.11
Jtekt ≫ Pc10p-dp Firmware Version < 1.50
Jtekt ≫ Pc10p-dp-io Firmware Version < 1.50
Jtekt ≫ Plus Bus-ex Firmware Version < 2.13
Jtekt ≫ Nano 10gx Firmware Version < 3.00
Jtekt ≫ Nano 2et Firmware Version < 2.40
Jtekt ≫ Pc10pe Firmware Version < 1.02
Jtekt ≫ Pc10pe-16/16p Firmware Version < 1.02
Jtekt ≫ Pc10e Firmware Version < 1.02
Jtekt ≫ Fl/et-t-v2h Firmware Version < f2.8_e1.5
Jtekt ≫ Pc10b Firmware Version < 1.11
Jtekt ≫ Pc10b-p Firmware Version < 1.11
Jtekt ≫ Nano Cpu Firmware Version < 2.08
Jtekt ≫ Pc10p Firmware Version < 1.05
Jtekt ≫ Pc10ge Firmware Version < 1.04
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.462 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.