CVE-2021-27417
Last modified
CVE-2021-27417 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ecoscentric | Ecospro | >= 2.0.1, <= 4.5.3 |
References
- https://bugzilla.ecoscentric.com/show_bug.cgi?id=1002437Permissions Required, Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04Third Party Advisory, US Government Resource
- https://bugzilla.ecoscentric.com/show_bug.cgi?id=1002437Permissions Required, Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-27417?
How severe is CVE-2021-27417?
How do I fix CVE-2021-27417?
Are you affected by CVE-2021-27417?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
