{"api_version":"1","generated_at":"2026-07-23T13:47:57+00:00","cve":"CVE-2021-27417","urls":{"html":"https://cve.report/CVE-2021-27417","api":"https://cve.report/api/cve/CVE-2021-27417.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-27417","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-27417"},"summary":{"title":"CVE-2021-27417","description":"eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2022-05-03 21:15:00","updated_at":"2022-05-12 15:38:00"},"problem_types":["CWE-190"],"metrics":[],"references":[{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04","name":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04","refsource":"CONFIRM","tags":[],"title":"Multiple RTOS (Update D) | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.ecoscentric.com/show_bug.cgi?id=1002437","name":"https://bugzilla.ecoscentric.com/show_bug.cgi?id=1002437","refsource":"CONFIRM","tags":[],"title":"Log in to The Issue Management System","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-27417","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-27417","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"David Atch, Omri Ben Bassat, and Tamir Ariel from Microsoft Section 52, and the Azure Defender for IoT research group reported these vulnerabilities to CISA.","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"27417","vulnerable":"1","versionEndIncluding":"4.5.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecoscentric","cpe5":"ecospro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2021-27417","STATE":"PUBLIC","TITLE":"eCosCentric eCosPro RTOS Integer Overflow or Wraparound"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"eCosPro RTOS","version":{"version_data":[{"version_affected":"<=","version_name":" 2.0.1","version_value":"4.5.3"}]}}]},"vendor_name":"eCosCentric"}]}},"credit":[{"lang":"eng","value":"David Atch, Omri Ben Bassat, and Tamir Ariel from Microsoft Section 52, and the Azure Defender for IoT research group reported these vulnerabilities to CISA."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":4.6,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-190 Integer Overflow or Wraparound"}]}]},"references":{"reference_data":[{"name":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04","refsource":"CONFIRM","url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04"},{"name":"https://bugzilla.ecoscentric.com/show_bug.cgi?id=1002437","refsource":"CONFIRM","url":"https://bugzilla.ecoscentric.com/show_bug.cgi?id=1002437"}]},"solution":[{"lang":"eng","value":"Update eCosCentric eCosPro RTOS to version 4.5.4 or newer – Update available"}],"source":{"defect":["“BadAlloc”"],"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-05-03 21:15:00","lastModifiedDate":"2022-05-12 15:38:00","problem_types":["CWE-190"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ecoscentric:ecospro:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.1","versionEndIncluding":"4.5.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"27417","Ordinal":"202523","Title":"CVE-2021-27417","CVE":"CVE-2021-27417","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"27417","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}