CVE-2021-27458

HIGH

JTEKT Corporation TOYOPUC - Path Traversal

Title source: llm
STIX 2.1

Description

If Ethernet communication of the JTEKT Corporation TOYOPUC product series’ (TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All versions, PC10GE TCC-6464: All versions, PC10P TCC-6372: All versions, PC10P-DP TCC-6726: All versions, PC10P-DP-IO TCC-6752: All versions, PC10B-P TCC-6373: All versions, PC10B TCC-1021: All versions, PC10B-E/C TCU-6521: All versions, PC10E TCC-4737: All versions; TOYOPUC-Plus Series: Plus CPU TCC-6740: All versions, Plus EX TCU-6741: All versions, Plus EX2 TCU-6858: All versions, Plus EFR TCU-6743: All versions, Plus EFR2 TCU-6859: All versions, Plus 2P-EFR TCU-6929: All versions, Plus BUS-EX TCU-6900: All versions; TOYOPUC-PC3J/PC2J Series: FL/ET-T-V2H THU-6289: All versions, 2PORT-EFR THU-6404: All versions) are left in an open state by an attacker, Ethernet communications cannot be established with other devices, depending on the settings of the link parameters.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-103-03

Scores

CVSS v3 7.5
EPSS 0.0111
EPSS Percentile 61.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-404
Status published
Products (18)
jtekt/2port-efr_thu-6404_firmware
jtekt/fl\/et-t-v2h_thu-6289_firmware
jtekt/pc10b-e\/c_tcu-6521_firmware
jtekt/pc10b-p_tcc-6373_firmware
jtekt/pc10b_tcc-1021_firmware
jtekt/pc10e_tcc-4737_firmware
jtekt/pc10g-cpu_tcc-6353_firmware
jtekt/pc10ge_tcc-6464_firmware
jtekt/pc10p-dp-io_tcc-6752_firmware
jtekt/pc10p-dp_tcc-6726_firmware
... and 8 more
Published Apr 19, 2021
Tracked Since Feb 18, 2026