Denial-of-Service Vulnerability in HMI GC-A2 Series from JTEKT
CVE-2023-49140

7.5HIGH

What is CVE-2023-49140?

A denial-of-service vulnerability has been identified in the commplex-link service of JTEKT’s HMI GC-A2 series. This issue allows a remote unauthenticated attacker to send specially crafted packets to specific ports, potentially disrupting normal operation and leading to service outages. It is crucial for organizations using this product to apply necessary security measures to mitigate this risk.

Affected Version(s)

GC-A22W-CW all versions

GC-A24 all versions

GC-A24-M all versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.