An out-of-bounds read vulnerability exists in the PORT command parameter...
Vulnerability Description
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no IP address argument is provided to the `PORT` command.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-46377
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Discovered by Kelly Leuschner of Cisco Talos.
References
More from Weston Embedded
View All →Affected Vendor
Weston Embedded
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.