Jtekt is an industrial automation and control systems vendor whose vulnerability footprint centers on a moderate portfolio of programmable logic controller and industrial gateway products including the Screen Creator Advance series and GC-A series devices. The vendor's disclosures cluster around memory-safety and resource-management weakness classes including out-of-bounds reads and writes, use-after-free conditions, and uncontrolled resource consumption, reflecting the embedded and firmware nature of these control-system platforms. A meaningful share of these vulnerabilities reach critical severity, underscoring the potential impact of flaws in devices that operate industrial processes and infrastructure. Defenders tracking operational-technology environments should monitor this vendor's advisories and prioritize patching for internet-accessible or network-connected instances of these industrial controllers; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jtekt over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29958CRITICAL JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects a | Jul 26, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-29951CRITICAL JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of | Jul 26, 2022 | 9.1 | 27 | NO | NO |
CVE-2023-25755HIGH Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check o | Apr 11, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-27648HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of KOYO Screen Creator 0.1.1.1. User interaction is required to exploit this vulnerab | Mar 29, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-22424HIGH Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. With the abnormal value given as th | Mar 6, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-22421HIGH Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. The insufficient buffer size fo | Mar 6, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-22419HIGH Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. When processing a comment block | Mar 6, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-22353HIGH Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing control management inf | Feb 13, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-22345HIGH Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process when out of specification errors are detec | Feb 13, 2023 | 7.8 | 24 | NO | NO |
CVE-2021-27458HIGH If Ethernet communication of the JTEKT Corporation TOYOPUC product series’ (TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All versions, PC10GE TCC-6464: All versions, PC10P TCC-6372: Al | Apr 19, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jtekt.
Media articles that mention a CVE ID that affects a product developed by Jtekt — matched by CVE ID, not by vendor name.