Impact
A stack-based buffer overflow flaw exists in the Remote I/O Coupler Unit (Server Type) CPSN‑MCB271‑*. When a remote attacker sends a specially crafted request, the overflow can corrupt the local stack and lead to a denial‑of‑service condition. This vulnerability falls under CWE‑121 and permits an attacker to terminate the service without compromising confidentiality or integrity of data.
Affected Systems
The issue affects Contec Co., Ltd. Remote I/O Coupler Units of the Server Type, specifically any model matching The product runs on the device’s embedded firmware and is intended for remote control and monitoring functions.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, and the EPSS score is <1%. The vulnerability is not listed in CISA’s KEV catalog. Although exploitation requires remote network access and the ability to send a crafted packet, no public exploit code has been disclosed. The likely attack vector is remote network-based intrusion targeting exposed service endpoints, and mitigation hinges on applying the firmware update released by Contec.
OpenCVE Enrichment