On Patlite NH-FB series devices through 1.46, remote attackers can cause a denial of service by omitting the query string. NOTE: the vendor's perspective is that "omitting the query string does not cause a denial of service and the indicated event can not be reproduced.
References
Link | Resource |
---|---|
https://packetstormsecurity.com/files/167797/Patlite-1.46-Buffer-Overflow.html | Exploit Third Party Advisory VDB Entry |
https://www.patlite.co.jp/product/detail0000021462.html | Product Vendor Advisory |
https://www.patlite.com/network-products/lineup/nh-fb.html | Product Vendor Advisory |
https://packetstormsecurity.com/files/167797/Patlite-1.46-Buffer-Overflow.html | Exploit Third Party Advisory VDB Entry |
https://www.patlite.co.jp/product/detail0000021462.html | Product Vendor Advisory |
https://www.patlite.com/network-products/lineup/nh-fb.html | Product Vendor Advisory |
Configurations
History
21 Nov 2024, 07:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://packetstormsecurity.com/files/167797/Patlite-1.46-Buffer-Overflow.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://www.patlite.co.jp/product/detail0000021462.html - Product, Vendor Advisory | |
References | () https://www.patlite.com/network-products/lineup/nh-fb.html - Product, Vendor Advisory |
07 Nov 2023, 03:49
Type | Values Removed | Values Added |
---|---|---|
Summary | On Patlite NH-FB series devices through 1.46, remote attackers can cause a denial of service by omitting the query string. NOTE: the vendor's perspective is that "omitting the query string does not cause a denial of service and the indicated event can not be reproduced. |
Information
Published : 2022-07-27 21:15
Updated : 2024-11-21 07:11
NVD link : CVE-2022-35911
Mitre link : CVE-2022-35911
CVE.ORG link : CVE-2022-35911
JSON object : View
Products Affected
patlite
- nhl-fb2_firmware
- nhl-fb2
- nhp-fb2_firmware
- nhp-fb2
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer