** DISPUTED ** On Patlite NH-FB series devices through 1.46, remote attackers can cause a denial of service by omitting the query string. NOTE: the vendor's perspective is that "omitting the query string does not cause a denial of service and the indicated event can not be reproduced."
References
Link | Resource |
---|---|
https://www.patlite.co.jp/product/detail0000021462.html | Product Vendor Advisory |
https://www.patlite.com/network-products/lineup/nh-fb.html | Product Vendor Advisory |
https://packetstormsecurity.com/files/167797/Patlite-1.46-Buffer-Overflow.html | Exploit Third Party Advisory VDB Entry |
Information
Published : 2022-07-27 14:15
Updated : 2022-09-02 20:59
NVD link : CVE-2022-35911
Mitre link : CVE-2022-35911
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
patlite
- nhp-fb2
- nhp-fb2_firmware
- nhl-fb2
- nhl-fb2_firmware