First published: Wed May 10 2023(Updated: )
An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Weston-embedded Uc-ftps | =1.98.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41985 is an authentication bypass vulnerability in Weston Embedded uC-FTPs v1.98.00.
The severity of CVE-2022-41985 is high with a CVSS score of 7.5.
An attacker can send a sequence of unauthenticated packets to bypass authentication and cause denial of service.
Weston Embedded uC-FTPs v1.98.00 is affected by CVE-2022-41985.
Apply the patch provided by Weston-embedded or upgrade to a version that includes the fix.