# CVE-2021-40402

## Summary

- **CVE ID:** CVE-2021-40402
- **Severity:** CRITICAL
- **CVSS Score:** 9.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H)
- **CWE:** CWE-755
- **Published:** Apr 14, 2022
- **Last Modified:** Mar 13, 2026

## Description

An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 and 2.8.0. A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

## Affected Products

- Gerbv — Gerbv (2.7.0)
- Gerbv — Gerbv (dev  (commit b5f1eacd))
- Gerbv — Gerbv forked (2.7.1)
- Gerbv — Gerbv forked (2.8.0)

## References

- [CNA](https://talosintelligence.com/vulnerability_reports/TALOS-2021-1416)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 43.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._