Impact
This vulnerability is an out-of-bounds write in the CONPROSYS nano Series firmware. A specially crafted request sent by a remote attacker can cause the system to crash, leading to a denial-of-service condition. The weakness is identified as CWE-787 and could be leveraged to stop the normal operation of the affected device.
Affected Systems
The affected devices are Contec Co., Ltd. programmable remote I/O coupler units of the CONPROSYS nano Series, specifically the CPSN-PCB271-S1-041, the CPSN‑EOB471EI‑[]1 Ethernet/IP Adapter, and the CPSN‑MCB271‑* server‑type units. No specific firmware or software versions were provided in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attacker must send a crafted packet over the network interface to trigger the overflow; the attack vector is therefore remote network access. No specific conditions are listed beyond the ability to send a malformed request.
OpenCVE Enrichment