Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21280

Опубликовано: 18 июн. 2021
Источник: nvd
CVSS3: 8.6
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bounds write in versions of Contiki-NG prior to 4.6 when transmitting a 6LoWPAN packet with a chain of extension headers. Unfortunately, the written header is not checked to be within the available space, thereby making it possible to write outside the buffer. The problem has been patched in Contiki-NG 4.6. Users can apply the patch for this vulnerability out-of-band as a workaround.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:contiki-ng:contiki-ng:*:*:*:*:*:*:*:*
Версия до 4.6 (исключая)

EPSS

Процентиль: 61%
0.00413
Низкий

8.6 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-787

EPSS

Процентиль: 61%
0.00413
Низкий

8.6 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-787