CVE-2021-27477

HIGHCVSS 7.5/10EPSS 1.13%

Last modified

CVE-2021-27477 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a receive buffer for FL-net are overwritten. As a result, the PLC CPU detects a system error, and the affected products stop.. EPSS estimates a 1.13% chance of exploitation in the next 30 days.

Description

When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a receive buffer for FL-net are overwritten. As a result, the PLC CPU detects a system error, and the affected products stop.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.13%

62.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JtektPc10g-Cpu Firmware< 3.91
Jtekt2port-Efr Firmware< 1.50
JtektPlus Cpu Firmware< 3.11
JtektPlus Ex Firmware< 3.11
JtektPlus Ex2 Firmware< 3.11
JtektPlus Efr Firmware< 3.11
JtektPlus Efr2 Firmware< 3.11
JtektPlus 2p-Efr Firmware< 3.11
JtektPc10p-Dp Firmware< 1.50
JtektPc10p-Dp-Io Firmware< 1.50
JtektPlus Bus-Ex Firmware< 2.13
JtektNano 10gx Firmware< 3.00
JtektNano 2et Firmware< 2.40
JtektPc10pe Firmware< 1.02
JtektPc10pe-16\/16p Firmware< 1.02
JtektPc10e Firmware< 1.02
JtektFl\/Et-T-V2h Firmware< f2.8_e1.5
JtektPc10b Firmware< 1.11
JtektPc10b-P Firmware< 1.11
JtektNano Cpu Firmware< 2.08
JtektPc10p Firmware< 1.05
JtektPc10ge Firmware< 1.04

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-27477?
When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a receive buffer for FL-net are overwritten. As a result, the PLC CPU detects a system error, and the affected products stop.
How severe is CVE-2021-27477?
CVE-2021-27477 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.13% probability of exploitation in the next 30 days.
How do I fix CVE-2021-27477?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-27477?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST