CVE-2021-27500: EIPStackGroup OpENer Ethernet/IP Reachable Assertion
Published May 12, 2022
·Updated
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
Affected Software
2 affected components
Opener Project Opener<=2.3
: EIPStackGroup https://github.com/EIPStackGroup/OpENer/ commits and versions prior to Feb 10, 2021
Remediation
Information
The maintainer of OpENer recommends those affected to apply the latest commits available.
Event History
May 12, 2022
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-27500?
CVE-2021-27500 is a vulnerability found in EIPStackGroup OpENer EtherNet/IP that can be exploited by an attacker to cause a denial-of-service (DoS) condition.
2
How does CVE-2021-27500 affect OpENer EtherNet/IP?
CVE-2021-27500 affects OpENer EtherNet/IP versions prior to Feb 10, 2021, allowing an attacker to send a specially crafted packet to cause a DoS condition.
3
What is the severity of CVE-2021-27500?
CVE-2021-27500 has a severity rating of high, with a severity value of 7.5.
4
What is the Common Weakness Enumeration (CWE) ID of CVE-2021-27500?
The CWE ID of CVE-2021-27500 is CWE-617.
5
How can I fix CVE-2021-27500?
To fix CVE-2021-27500, it is recommended to update EIPStackGroup OpENer EtherNet/IP to a version released after Feb 10, 2021.