CVE-2021-27477

When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a receive buffer for FL-net are overwritten. As a result, the PLC CPU detects a system error, and the affected products stop.
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-180-04 Third Party Advisory US Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-180-04 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:jtekt:pc10g-cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10g-cpu:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:jtekt:2port-efr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:2port-efr:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:jtekt:plus_cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_cpu:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:jtekt:plus_ex_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_ex:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:jtekt:plus_ex2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_ex2:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:jtekt:plus_efr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_efr:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:jtekt:plus_efr2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_efr2:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:jtekt:plus_2p-efr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_2p-efr:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:jtekt:pc10p-dp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10p-dp:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:jtekt:pc10p-dp-io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10p-dp-io:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:jtekt:plus_bus-ex_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_bus-ex:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:jtekt:nano_10gx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:nano_10gx:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:jtekt:nano_2et_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:nano_2et:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:jtekt:pc10pe_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10pe:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:jtekt:pc10pe-16\/16p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10pe-16\/16p:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:jtekt:pc10e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10e:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:jtekt:fl\/et-t-v2h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:fl\/et-t-v2h:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:jtekt:pc10b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10b:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:jtekt:pc10b-p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10b-p:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:jtekt:nano_cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:nano_cpu:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:jtekt:pc10p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10p:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:jtekt:pc10ge_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10ge:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:58

Type Values Removed Values Added
References () https://us-cert.cisa.gov/ics/advisories/icsa-21-180-04 - Third Party Advisory, US Government Resource () https://us-cert.cisa.gov/ics/advisories/icsa-21-180-04 - Third Party Advisory, US Government Resource

07 Oct 2022, 19:16

Type Values Removed Values Added
CWE CWE-119 CWE-787

08 Jul 2021, 18:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 7.8
v3 : 7.5
CWE CWE-119
References (MISC) https://us-cert.cisa.gov/ics/advisories/icsa-21-180-04 - (MISC) https://us-cert.cisa.gov/ics/advisories/icsa-21-180-04 - Third Party Advisory, US Government Resource
CPE cpe:2.3:o:jtekt:2port-efr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_bus-ex:-:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:fl\/et-t-v2h:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_efr2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10pe_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10ge_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_efr:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_ex2:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10p-dp-io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:nano_10gx:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10p-dp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10pe-16\/16p:-:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10p-dp-io:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_ex2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_efr2:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_bus-ex_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10pe:-:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:nano_cpu:-:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10b:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10b-p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10ge:-:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_2p-efr:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_ex_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_efr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10b-p:-:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10p-dp:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10e:-:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10g-cpu:-:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:2port-efr:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:nano_10gx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10pe-16\/16p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:pc10p:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:pc10g-cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_cpu:-:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:plus_ex:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:nano_2et_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:plus_2p-efr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:fl\/et-t-v2h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jtekt:nano_2et:-:*:*:*:*:*:*:*
cpe:2.3:o:jtekt:nano_cpu_firmware:*:*:*:*:*:*:*:*

01 Jul 2021, 13:42

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-01 13:15

Updated : 2024-11-21 05:58


NVD link : CVE-2021-27477

Mitre link : CVE-2021-27477

CVE.ORG link : CVE-2021-27477


JSON object : View

Products Affected

jtekt

  • pc10e
  • nano_2et
  • nano_cpu_firmware
  • pc10pe
  • pc10pe-16\/16p
  • pc10g-cpu
  • pc10p-dp-io_firmware
  • plus_ex2_firmware
  • plus_bus-ex
  • plus_2p-efr
  • pc10ge_firmware
  • pc10b-p_firmware
  • fl\/et-t-v2h_firmware
  • pc10ge
  • plus_ex_firmware
  • plus_ex
  • plus_cpu
  • plus_cpu_firmware
  • nano_10gx
  • plus_efr
  • pc10pe-16\/16p_firmware
  • 2port-efr
  • pc10p-dp_firmware
  • pc10p_firmware
  • plus_2p-efr_firmware
  • pc10p-dp
  • pc10p-dp-io
  • plus_efr2_firmware
  • pc10b_firmware
  • plus_efr_firmware
  • plus_ex2
  • plus_bus-ex_firmware
  • pc10pe_firmware
  • nano_2et_firmware
  • pc10e_firmware
  • fl\/et-t-v2h
  • pc10b
  • pc10b-p
  • pc10p
  • pc10g-cpu_firmware
  • nano_10gx_firmware
  • 2port-efr_firmware
  • nano_cpu
  • plus_efr2
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-787

Out-of-bounds Write