Buffer Read Vulnerability in Siemens Devices Due to TFTP Misconfiguration
CVE-2022-46143
2.7LOW
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 13 December 2022
Summary
The vulnerability arises from Siemens devices failing to correctly validate the TFTP blocksize. An authenticated attacker can exploit this oversight to read from an uninitialized buffer, potentially exposing previously allocated data. This presents a significant security concern as it could lead to unauthorized access to sensitive information stored in the affected devices.
Affected Version(s)
RUGGEDCOM RM1224 LTE(4G) EU 0
RUGGEDCOM RM1224 LTE(4G) EU 0
RUGGEDCOM RM1224 LTE(4G) NAM 0
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved