CVE-2022-46377

MEDIUM

Weston Embedded uC-FTPs < 1.98.00 - DoS

Title source: llm
STIX 2.1

Description

An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no IP address argument is provided to the `PORT` command.

Scores

CVSS v3 6.5
EPSS 0.0052
EPSS Percentile 66.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-125 CWE-823
Status published
Products (1)
weston-embedded/uc-ftps 1.98.00
Published May 10, 2023
Tracked Since Feb 18, 2026