Impact
This vulnerability is an out-of-bounds write in the CONPROSYS nano Series firmware used by Contec’s Programmable Remote I/O Coupler Units, Remote I/O Coupler Units, and Server‑type units. A malicious remote actor can craft a specially built network request that triggers the memory corruption, which in turn causes the device firmware to crash and reboot, thus creating a denial‑of‑service condition.
Affected Systems
Affected hardware includes Contec Co., Ltd. products: the CPSN‑PCB271‑S1‑041 Programmable Remote I/O Coupler Unit, the CPSN‑EOB471EI‑[]1 Ethernet/I P Adapter, and any CPSN‑MCB271‑* Server‑type units. The advisory does not specify firmware or operating system versions, so all units running the CONPROSYS nano Series firmware are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 signals moderate severity, while the EPSS score of < 1 % indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The attack vector appears to be remote network access: a network attacker must send a crafted packet to the device’s network interface to trigger the overflow. No special privileges or local access are required; a simple network connection suffices.
OpenCVE Enrichment