Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.
https://cert-portal.siemens.com/productcert/pdf/ssa-413565.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf
https://cert-portal.siemens.com/productcert/html/ssa-413565.html
https://cert-portal.siemens.com/productcert/html/ssa-180704.html