Vulnerabilities in contiki-ng
32 resultsVexday analysis
Contiki-NG apresenta 29 vulnerabilidades catalogadas, mas nenhuma sob exploração ativa conhecida (KEV=0), reduzindo significativamente o risco imediato. A fraqueza dominante é leitura fora dos limites (CWE-125), com apenas 1 vulnerabilidade crítica, e nenhuma publicação nos últimos 90 dias indica que o risco não é contemporâneo. O perfil sugere exposure controlado, adequado para ambientes que já mitigaram as falhas mais graves.
CVE-2023-50927HIGHInsufficient boundary checks for DIO and DAO messages in RPL-Lite in Contiki-NGEPSS 0.5%CVE-2023-34101HIGHContiki-NG vulnerable to out-of-bounds read when processing ICMP DAO inputEPSS 0.5%CVE-2023-34100HIGHOut-of-Bounds Read in contiki-ngEPSS 0.4%CVE-2023-48229HIGHOut-of-bounds write in the radio driver for Contiki-NG nRF platformsEPSS 0.4%CVE-2023-37281MEDIUMOut-of-bounds read during IPHC address decompressionEPSS 0.4%CVE-2023-37459MEDIUMOut-of-bounds read when processing a received IPv6 packetEPSS 0.4%CVE-2023-23609HIGHcontiki-ng BLE-L2CAP contains Improper size validation of L2CAP framesEPSS 0.4%CVE-2024-41126HIGHOut-of-bounds read when decoding SNMP messages in Contiki-NGEPSS 0.3%CVE-2024-41125HIGHOut-of-bounds read in SNMP when decoding a string in Contiki-NGEPSS 0.3%CVE-2026-5856HIGHContiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Traversal Before Transaction-ID ValidationEPSS 0.3%CVE-2022-41873MEDIUMOut-of-bounds read and write in BLE L2CAP moduleEPSS 0.2%CVE-2022-41972LOWContiki-NG contains NULL Pointer Dereference in BLE L2CAP moduleEPSS 0.2%