CVE-2021-27417

MEDIUM

eCosCentric eCosPro RTOS <4.5.3 - Buffer Overflow

Title source: llm
STIX 2.1

Description

eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04
Permissions Required, Vendor Advisory x_refsource_confirm
https://bugzilla.ecoscentric.com/show_bug.cgi?id=1002437

Scores

CVSS v3 4.6
EPSS 0.0053
EPSS Percentile 40.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (1)
ecoscentric/ecospro 2.0.1 - 4.5.3
Published May 03, 2022
Tracked Since Feb 18, 2026