Vulnerabilities > CVE-2022-46143 - Improper Validation of Specified Quantity in Input vulnerability in Siemens products

047910
CVSS 2.7 - LOW
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
siemens
CWE-1284

Summary

Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.

Vulnerable Configurations

Part Description Count
OS
Siemens
101
Hardware
Siemens
101