PatchSiren cyber security CVE debrief
CVE-2021-27500 Festo CVE debrief
CVE-2021-27500 is a denial-of-service issue in affected Festo devices using the EIPStackGroup OpENer EtherNet/IP stack. According to the CISA CSAF advisory, a specifically crafted packet can disrupt versions prior to 2021-02-10. The advisory covers multiple Festo SBRD-Q, SBOC-Q, and SBOI-Q product variants and states that no fix is planned, so mitigation depends on reducing exposure and disabling EtherNet/IP where it is not needed.
- Vendor
- Festo
- Product
- Hardware
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2021-09-22
- Original CVE updated
- 2025-08-26
- Advisory published
- 2021-09-22
- Advisory updated
- 2025-08-26
Who should care
OT and ICS operators using the affected Festo SBRD-Q, SBOC-Q, or SBOI-Q hardware/firmware; plant engineers; industrial network administrators; and security teams responsible for segmentation and exposure management of EtherNet/IP-enabled equipment.
Technical summary
The advisory describes a network-reachable availability issue in the EIPStackGroup OpENer EtherNet/IP stack used by affected Festo products. An attacker who sends a specifically crafted packet may cause a denial-of-service condition. The source advisory ties the issue to versions prior to 2021-02-10 and lists numerous affected product and firmware entries across the SBRD-Q, SBOC-Q, and SBOI-Q families.
Defensive priority
High for environments where the affected devices are reachable from broader OT or IT networks. The primary impact is loss of availability, and the advisory indicates there is no fix planned, making compensating controls the main defense.
Recommended defensive actions
- Inventory Festo SBRD-Q, SBOC-Q, and SBOI-Q devices and confirm whether affected firmware is present.
- Minimize network exposure for all control system devices and ensure they are not accessible from the Internet.
- Deactivate EtherNet/IP in device settings if it is not required for operations.
- Use network segmentation, access control, and allowlisting to restrict who can reach affected devices.
- Monitor OT network traffic for unexpected EtherNet/IP activity and validate that compensating controls remain in place because no fix is planned.
Evidence notes
The source corpus is the CISA CSAF advisory ICSA-25-273-02 and its referenced official vendor/advisory links. The advisory published on 2021-09-22 and was later revised on 2025-08-26; that revision date should not be treated as the vulnerability’s issue date. The advisory states that a specifically crafted packet can cause denial of service and that there is no fix planned. Mitigation guidance in the advisory is to minimize exposure and disable EtherNet/IP if unused.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-27500 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-27500
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-27500 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-27500
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-273-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2021/fsa-202101.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2021-045/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-273-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.