Denial-of-Service Vulnerability in HMI GC-A2 Series by JTEKT
CVE-2023-41963

7.5HIGH

What is CVE-2023-41963?

A denial-of-service vulnerability has been identified in the FTP service of JTEKT's HMI GC-A2 series. An unauthenticated attacker remotely can send specially crafted packets to certain ports, potentially leading to a DoS condition that disrupts the normal functionality of the affected devices. This issue emphasizes the need for prompt security measures to protect systems from unauthorized access and ensure operational continuity.

Affected Version(s)

GC-A22W-CW all versions

GC-A24 all versions

GC-A24-M all versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.