First published: Wed May 10 2023(Updated: )
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no port argument is provided to the `PORT` command.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Weston-embedded Uc-ftps | =1.98.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46378 is an out-of-bounds read vulnerability in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00.
The severity of CVE-2022-46378 is high with a CVSS score of 7.5.
CVE-2022-46378 can lead to denial of service due to an out-of-bounds read vulnerability in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00.
An attacker can exploit CVE-2022-46378 by sending specially-crafted network packets to trigger the out-of-bounds read vulnerability in the affected software.
Yes, a fix is available for CVE-2022-46378. It is recommended to update to a patched version of Weston Embedded uC-FTPs.