ZeroHour

CVE-2021-27458

CVSS 3.1
7.5 high
EPSS
1%p64
Published
()
Modified
Description

If Ethernet communication of the JTEKT Corporation TOYOPUC product series’ (TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All versions, PC10GE TCC-6464: All versions, PC10P TCC-6372: All versions, PC10P-DP TCC-6726: All versions, PC10P-DP-IO TCC-6752: All versions, PC10B-P TCC-6373: All versions, PC10B TCC-1021: All versions, PC10B-E/C TCU-6521: All versions, PC10E TCC-4737: All versions; TOYOPUC-Plus Series: Plus CPU TCC-6740: All versions, Plus EX TCU-6741: All versions, Plus EX2 TCU-6858: All versions, Plus EFR TCU-6743: All versions, Plus EFR2 TCU-6859: All versions, Plus 2P-EFR TCU-6929: All versions, Plus BUS-EX TCU-6900: All versions; TOYOPUC-PC3J/PC2J Series: FL/ET-T-V2H THU-6289: All versions, 2PORT-EFR THU-6404: All versions) are left in an open state by an attacker, Ethernet communications cannot be established with other devices, depending on the settings of the link parameters.

Vendors
jtekt
Products
pc10g-cpu tcc-6353 firmware, pc10ge tcc-6464 firmware, pc10p tcc-6372 firmware, pc10p-dp tcc-6726 firmware, pc10p-dp-io tcc-6752 firmware, pc10b-p tcc-6373 firmware, pc10b tcc-1021 firmware, pc10b-e\/c tcu-6521 firmware, pc10e tcc-4737 firmware, plus cpu tcc-6740 firmware, plus ex tcu-6741 firmware, plus ex2 tcu-6858 firmware
Weakness
CWE-404
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.