The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) an
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS 벡터 정보 없음
약점 (CWE)
상세 설명
The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than
four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not
against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one
missing check, both reachable before any authentication because TFTP has none.
The handler passes nx_packet_length - 4 straight to FileX:
1 2 3 4/* addons/tftp/nxd_tftp_server.c:1863, 1889 */ 5 6 7 8status = nx_packet_copy(packet_ptr, &temp_ptr, 9 10 server_ptr -> nx_tftp_server_packet_pool_ptr, NX_WAIT_FOREVER);11 12 13...14 15 16 17fx_file_write(&(client_request_ptr -> nx_tftp_client_request_file),18 19 packet_ptr -> nx_packet_prepend_ptr + 4,20 packet_ptr -> nx_packet_length - 4);21 nx_packet_length is the length of a chain, not of one contiguous buffer, so FileX copies past the
end of the first packet:
1 2 3 4ERROR: AddressSanitizer: heap-buffer-overflow 5 6 7 8READ of size 1280 at 0x621000001108 thread T5 9 10 #0 __interceptor_memcpy11 #1 _fx_utility_memory_copy filex/common/src/fx_utility_memory_copy.c:7812 13 140x621000001108 is 0 bytes to the right of 4104-byte region15 16 Those bytes are written into the file the attacker is uploading, and a TFTP read request hands them
back, so this is a memory disclosure with a convenient retrieval channel.
The same datagram also wedges the server. nx_packet_copy at :1863 needs
ceil(nx_packet_length / pool_payload) packets and asks for them with NX_WAIT_FOREVER, so when the
attacker sizes the datagram beyond what the pool holds, the server thread suspends and never
returns. A liveness probe after one such datagram times out with the pool at 0 of 12 packets and
the server thread suspended, and no later client is served.
Reject nx_packet_length > 4 + NX_TFTP_FILE_TRANSFER_MAX in the DATA branch before either call,
and use a bounded wait rather than NX_WAIT_FOREVER for the copy.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.