RobotRisk Autonomous Systems Incident & Risk Register
RobotRisk / FANUC / 2021-08-31

CISA advisory: buffer overflow / integer coercion vulnerabilities in FANUC robot controllers

S1 · 08/31
2021 · FANUC

Record

CompanyFANUC
Categorymachinery oem
Typecyber
Date08/31
2021
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
SeverityS1 (near-miss / disclosed vulnerability)
ScaleFANUC robot controller product line
Confidencehigh
VerificationCited source on file; not independently re-verified
SourceCISA ICS-CERT

What happened

CISA published ICSA-21-243-02 describing vulnerabilities in FANUC robot controllers that could crash the device or, via buffer overflow, potentially allow remote code execution; no known public exploitation, vendor patch/mitigation issued.

FANUC record context

Entries by year and severity

012015 S5: 11152021 S1: 11212026 S1: 1126
S1S2S3S4S5

By incident type

By severity

FANUC vs machinery oem alternatives

machinery oem context

machinery oem: entries by year

232015 S5: 22152017 S2: 11172021 S1: 22212024 S1: 11242026 S1: 3326
S1S2S3S4S5

machinery oem: failure modes

machinery oem: most entries

cyber context

cyber: by category

cyber: by year

cyber: severity profile

Comparable cyber events in machinery oem

SevDateCompanyEvent
S12026-09Mitsubishi Electric (Automation)CISA ICS advisories: 1 affecting robot/controller products
S12026-09FANUCCISA ICS advisories: 2 affecting robot/controller products
S12026-09ABBCISA ICS advisories: 2 affecting robot/controller products
S12021-07-27KUKACISA advisory: hard-coded credentials in KUKA KR C4 robot controller (CVSS 9.8)
S22017-05ABBResearchers demonstrate remote hack of ABB IRB140 industrial robot causing unsafe physical movement

Other FANUC entries

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs