The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass denial-of-service attack on all CME8000 devices connected to the same network.
History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:10:19.613Z

Reserved: 2022-08-29T00:00:00.000Z

Link: CVE-2022-38100

cve-icon Vulnrichment

Updated: 2024-08-03T10:45:52.412Z

cve-icon NVD

Status : Modified

Published: 2022-09-13T15:15:08.843

Modified: 2024-11-21T07:15:47.503

Link: CVE-2022-38100

cve-icon Redhat

No data.