VYPR

Vendor CVEs

Jtekt Electronics Corporation

All CVEs

28 total · sorted by risk
  • CVE-2022-29958CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with…

  • CVE-2022-29951CriJul 26, 2022
    risk 0.59cvss 9.1epss 0.01

    JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and…

  • CVE-2024-47136HigOct 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and…

  • CVE-2024-47135HigOct 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version…

  • CVE-2023-42507HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow vulnerability exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.

  • CVE-2023-42506HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper restriction of operations within the bounds of a memory buffer issue exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2…

  • CVE-2023-41375HigSep 20, 2023
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability exists in Kostac PLC Programming Software Version 1.6.11.0. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue…

  • CVE-2023-41374HigSep 20, 2023
    risk 0.51cvss 7.8epss 0.00

    Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue…

  • CVE-2023-25755HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check of its data size when processing a project file. If a user of Screen Creator Advance 2 opens a…

  • CVE-2022-27648HigMar 29, 2023
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of KOYO Screen Creator 0.1.1.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2023-22424HigMar 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. With the abnormal value given as the maximum number of columns for the PLC program, the process accesses the freed memory. As a…

  • CVE-2023-22421HigMar 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. The insufficient buffer size for the PLC program instructions leads to out-of-bounds read. As a result, opening a specially…

  • CVE-2023-22419HigMar 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. When processing a comment block in stage information, the end of data cannot be verified and out-of-bounds read occurs. As a…

  • CVE-2023-22360HigFeb 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information…

  • CVE-2023-22353HigFeb 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing control management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may…

  • CVE-2023-22350HigFeb 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing parts management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead…

  • CVE-2023-22349HigFeb 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing screen management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may…

  • CVE-2023-22347HigFeb 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing file structure information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead…

  • CVE-2023-22346HigFeb 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing template information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to…

  • CVE-2023-22345HigFeb 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process when out of specification errors are detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to…

  • CVE-2023-49713HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-49143HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in rfe service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-49140HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-41963HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in FTP service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2021-27477HigJul 1, 2021
    risk 0.49cvss 7.5epss 0.01

    When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive…

  • CVE-2021-27458HigApr 19, 2021
    risk 0.49cvss 7.5epss 0.01

    If Ethernet communication of the JTEKT Corporation TOYOPUC product series’ (TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All versions, PC10GE TCC-6464: All versions, PC10P TCC-6372: All versions, PC10P-DP TCC-6726: All versions, PC10P-DP-IO TCC-6752: All versions, PC10B-P…

  • CVE-2025-24317MedApr 4, 2025
    risk 0.34cvss 5.3epss 0.01

    Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.

  • CVE-2021-33011MedSep 10, 2021
    risk 0.28cvss 4.3epss 0.00

    All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be able to properly process an ICMP flood, which may allow an attacker to deny Ethernet communications between affected devices.