2021-36762 | InterNiche NicheStack TFTP Packet tfshnd:tftpsrv.c out-of-bounds read
CVSS Meta Temp Score | Current Exploit Price (≈) | CTI Interest Score |
---|---|---|
5.1 | $0-$5k | 0.47 |
A vulnerability classified as problematic has been found in InterNiche NicheStack up to 4.3. This affects the function tfshnd:tftpsrv.c
of the component TFTP Packet Handler. The manipulation with an unknown input leads to a information disclosure vulnerability. CWE is classifying the issue as CWE-125. This is going to have an impact on confidentiality. The summary by CVE is:
An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing function doesn’t ensure that a filename is adequately ‘