#VU61206 Improper Neutralization of Null Byte or NUL Character in PHICOMM products - CVE-2022-25219

 

#VU61206 Improper Neutralization of Null Byte or NUL Character in PHICOMM products - CVE-2022-25219

Published: March 9, 2022


Vulnerability identifier: #VU61206
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-25219
CWE-ID: CWE-158
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
K2
K3
K3C
K2 A7
K2G A1
Software vendor:
PHICOMM

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a null byte interaction error in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords. A remote attacker on the local network can use specially crafted UDP packets and make those ephemeral passwords predictable.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links