CVE-2021-27477

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
01/07/2021
Last modified:
07/10/2022

Description

When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a receive buffer for FL-net are overwritten. As a result, the PLC CPU detects a system error, and the affected products stop.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:jtekt:pc10g-cpu_firmware:*:*:*:*:*:*:*:* 3.91 (excluding)
cpe:2.3:h:jtekt:pc10g-cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:2port-efr_firmware:*:*:*:*:*:*:*:* 1.50 (excluding)
cpe:2.3:h:jtekt:2port-efr:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_cpu_firmware:*:*:*:*:*:*:*:* 3.11 (excluding)
cpe:2.3:h:jtekt:plus_cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_ex_firmware:*:*:*:*:*:*:*:* 3.11 (excluding)
cpe:2.3:h:jtekt:plus_ex:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_ex2_firmware:*:*:*:*:*:*:*:* 3.11 (excluding)
cpe:2.3:h:jtekt:plus_ex2:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_efr_firmware:*:*:*:*:*:*:*:* 3.11 (excluding)
cpe:2.3:h:jtekt:plus_efr:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_efr2_firmware:*:*:*:*:*:*:*:* 3.11 (excluding)
cpe:2.3:h:jtekt:plus_efr2:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_2p-efr_firmware:*:*:*:*:*:*:*:* 3.11 (excluding)


References to Advisories, Solutions, and Tools