CVE-2022-41985: High severity weston embedded uc-ftps vulnerability
Published May 10, 2023
·Updated
An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.
Affected Software
1 affected component
Weston-embedded Uc-ftps=1.98.00
Remediation
Patch Available
Event History
May 10, 2023
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-41985?
CVE-2022-41985 is an authentication bypass vulnerability in Weston Embedded uC-FTPs v1.98.00.
2
What is the severity of CVE-2022-41985?
The severity of CVE-2022-41985 is high with a CVSS score of 7.5.
3
How does the authentication bypass vulnerability in Weston Embedded uC-FTPs v1.98.00 work?
An attacker can send a sequence of unauthenticated packets to bypass authentication and cause denial of service.
4
Which software versions are affected by CVE-2022-41985?
Weston Embedded uC-FTPs v1.98.00 is affected by CVE-2022-41985.
5
How can I fix the authentication bypass vulnerability in Weston Embedded uC-FTPs v1.98.00?
Apply the patch provided by Weston-embedded or upgrade to a version that includes the fix.