CVE-2021-27478: EIPStackGroup OpENer Ethernet/IP Incorrect Conversion between Numeric Types
Published May 12, 2022
·Updated
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition.
Affected Software
2 affected components
Opener Project Opener<=2.3
: EIPStackGroup https://github.com/EIPStackGroup/OpENer/ commits and versions prior to Feb 10, 2021
Remediation
Information
The maintainer of OpENer recommends those affected to apply the latest commits available.
Event History
May 12, 2022
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-27478?
The severity of CVE-2021-27478 is high with a CVSS score of 7.5.
2
How does the vulnerability CVE-2021-27478 affect OpENer?
The vulnerability CVE-2021-27478 affects OpENer versions prior to Feb 10, 2021, and may cause a denial-of-service condition.
3
How can I mitigate the vulnerability CVE-2021-27478 in OpENer?
To mitigate the vulnerability CVE-2021-27478 in OpENer, upgrade to a version later than Feb 10, 2021.