CVE-2025-24317 Details
Description
Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.
A denial-of-service vulnerability has been identified in JTEKT ELECTRONICS CORPORATION's HMI ViewJet C-more series and HMI GC-A2 series. This vulnerability allows a remote, unauthenticated attacker to cause a denial-of-service condition by sending specially crafted packets to specific ports. The affected products require a manual restart to recover from the service disruption.
JTEKT ELECTRONICS CORPORATION has recommended users apply a workaround. When connecting the HMI to the Internet, use a firewall or virtual private network (VPN) to prevent unauthorized access. It is also advised to make the HMI accessible only within the internal network.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 4, 2025CISA-ADP
Assessed Apr 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN17260367/ | [email protected] | AdvisoryBundle |
| https://www.electronics.jtekt.co.jp/en/topics/202503207269/ | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.electronics.jtekt.co.jp/en/topics/202503207271/ | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| JTEKT ELECTRONICS CORPORATION HMI ViewJet C-more | All versions |
CPE
Remediation
| |
| JTEKT ELECTRONICS CORPORATION HMI GC-A2 | <= 0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 4, 2025 | New CVE Received | [email protected] |
Volerion