CVE-2022-46143 Vulnerability Details

  /     /     /  

CVE-2022-46143 Metadata Quick Info

CVE Published: 13/12/2022 | CVE Updated: 13/08/2024 | CVE Year: 2022
Source: siemens | Vendor: Siemens | Product: RUGGEDCOM RM1224 LTE(4G) EU
Status : PUBLISHED

CVE-2022-46143 Description

Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.

Metrics

CVSS Version: 3.1 | Base Score: 2.7 LOW
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-1284
CWE Name: CWE-1284: Improper Validation of Specified Quantity in Input
Source: Siemens

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).