VYPR
High severity7.0NVD Advisory· Published Jun 18, 2021· Updated Jun 17, 2026

CVE-2021-21281

CVE-2021-21281

Description

Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After establishing a TCP socket using the tcp-socket library, it is possible for the remote end to send a packet with a data offset that is unvalidated. The problem has been patched in Contiki-NG 4.6. Users can apply the patch for this vulnerability out-of-band as a workaround.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:o:contiki-ng:contiki-ng:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:contiki-ng:contiki-ng:*:*:*:*:*:*:*:*range: <4.6
    • (no CPE)range: < 4.6
  • Range: <4.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.