VYPR

Contiki Ng.

by Xwiki Contrib

Source repositories

CVEs (51)

  • CVE-2022-35927HigAug 4, 2022
    risk 0.00cvss 8.1epss 0.02

    Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol implementation in the Contiki-NG operating system, an incoming DODAG Information Option (DIO) control message can contain a prefix information option with a length…

  • CVE-2022-35926MedAug 4, 2022
    risk 0.00cvss 5.9epss 0.01

    Contiki-NG is an open-source, cross-platform operating system for IoT devices. Because of insufficient validation of IPv6 neighbor discovery options in Contiki-NG, attackers can send neighbor solicitation packets that trigger an out-of-bounds read. The problem exists in the…

  • CVE-2021-32771HigAug 4, 2022
    risk 0.00cvss 8.1epss 0.01

    Contiki-NG is an open-source, cross-platform operating system for IoT devices. In affected versions it is possible to cause a buffer overflow when copying an IPv6 address prefix in the RPL-Classic implementation in Contiki-NG. In order to trigger the vulnerability, the…

  • CVE-2020-12140HigDec 7, 2021
    risk 0.00cvss 8.8epss 0.01

    A buffer overflow in os/net/mac/ble/ble-l2cap.c in the BLE stack in Contiki-NG 4.4 and earlier allows an attacker to execute arbitrary code via malicious L2CAP frames.

  • CVE-2020-12141CriOct 19, 2021
    risk 0.00cvss 9.1epss 0.02

    An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentially disclose information via crafted SNMP packets to snmp_ber_decode_string_len_buffer in os/net/app-layer/snmp/snmp-ber.c.

  • CVE-2021-21410HigJun 18, 2021
    risk 0.00cvss 8.2epss 0.01

    Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be triggered by 6LoWPAN packets sent to devices running Contiki-NG 4.6 and prior. The IPv6 header decompression function (uncompress_hdr_iphc)…

  • CVE-2021-21281HigJun 18, 2021
    risk 0.00cvss 7.0epss 0.01

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After establishing a TCP socket using the tcp-socket library, it is possible for the remote end to send a…

  • CVE-2021-21280HigJun 18, 2021
    risk 0.00cvss 8.6epss 0.01

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bounds write in versions of Contiki-NG prior to 4.6 when transmitting a 6LoWPAN packet with a chain of extension headers. Unfortunately, the written…

  • CVE-2021-21257HigJun 18, 2021
    risk 0.00cvss 8.2epss 0.01

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. The RPL-Classic and RPL-Lite implementations in the Contiki-NG operating system versions prior to 4.6 do not validate the address pointer in the RPL source routing header This makes it…

  • CVE-2021-21282HigJun 18, 2021
    risk 0.00cvss 8.6epss 0.01

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, buffer overflow can be triggered by an input packet when using either of Contiki-NG's two RPL implementations in source-routing mode. The problem has been…

  • CVE-2019-9183HigApr 23, 2020
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. A buffer overflow is present due to an integer underflow during 6LoWPAN fragment processing in the face of truncated fragments in os/net/ipv6/sicslowpan.c. This results in accesses of unmapped memory,…

Page 3 of 3