https://us-cert.cisa.gov/ics/advisories/icsa-20-189-02IMPROPER RESTRICTION OF OPERATIONS WITHIN THE BOUNDS OF A MEMORY BUFFER CWE-119
The vulnerability could allow a malicious attacker to crash the device, which could lead to remote code execution.
SESSION FIXATION CWE-384
The vulnerability could allow a malicious attacker to cause a denial-of-service of TCP connection.
NULL POINTER DEREFERENCE CWE-476
The vulnerability could allow a malicious attacker to cause a denial-of-service condition and crash the device.
IMPROPER ACCESS CONTROL CWE-284
The vulnerability could allow a malicious attacker authentication to access sensitive resources, cause a denial-of-service condition, and crash the device.
IMPROPER NEUTRALIZATION OF ARGUMENT DELIMITERS IN A COMMAND ('ARGUMENT INJECTION') CWE-88
The vulnerability could allow an attacker to cause a denial-of-service condition.
RESOURCE MANAGEMENT ERRORS CWE-399
The vulnerability could allow an attacker to obtain sensitive information.