CVE-2022-46377 is an out-of-bounds read vulnerability in Weston Embedded uC-FTPs v1.98.00, specifically within the PORT command parameter extraction. This vulnerability, triggered when no IP address argument is provided to the PORT command, carries a CVSS score of 7.5 (High) due to its network attack vector, low complexity, and potential for denial of service. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it shows minimal community discussion or media coverage, suggesting it is not actively exploited or widely known.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.98.00CPE matchmatch criteria | cpe:2.3:a:weston-embedded:uc-ftps:1.98.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.