Medium severity6.5NVD Advisory· Published May 10, 2023· Updated Jun 17, 2026
CVE-2022-46378
CVE-2022-46378
Description
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no port argument is provided to the PORT command.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:weston-embedded:uc-ftps:1.98.00:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:weston-embedded:uc-ftps:1.98.00:*:*:*:*:*:*:*
- (no CPE)range: <=1.98.00
- (no CPE)range: v 1.98.00
Patches
Vulnerability mechanics
References
3- github.com/weston-embedded/uC-FTPs/pull/2nvdPatch
- talosintelligence.com/vulnerability_reports/TALOS-2022-1681nvdExploitMitigationThird Party Advisory
- www.talosintelligence.com/vulnerability_reports/TALOS-2022-1681nvd
News mentions
0No linked articles in our index yet.