CVE Database · CVE-2022-46143
CVSS v3.1
2.7
CVSS v4.0
5.1
EPSS
0.70%
Published
Dec 13, 2022
Modified
Jan 14, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NWeaknesses (CWE)
Affected Products (202)
References (6)
...and 152 more