VYPR

Wpantund

by Openthread

CVEs (2)

  • CVE-2021-33889MedJul 2, 2021
    risk 0.44cvss 6.8epss 0.00

    OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data type for metric_len.

  • CVE-2020-8916MedJul 7, 2020
    risk 0.00cvss 5.0epss 0.00

    A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the control driver (eg: debug environments) can allow an attacker to crash the service (DoS). We…