Vulnerabilidades en Contiki-NG

32 resultados
Análisis Vexday

Contiki-NG registra 3 vulnerabilidades na base Vexday, todas publicadas nos últimos 90 dias, com 1 classificada como crítica e nenhuma sob ataque ativo conhecido. A fraqueza dominante é leitura fora dos limites (CWE-125), típica de software embarcado, indicando risco recente que demanda atenção mas sem exploração ativa documentada no momento.

CVE-2022-35927HIGHUnverified DIO prefix info lengths in RPL-Classic in Contiki-NGEPSS 2.0%CVE-2021-32771HIGHBuffer overflow in contiki-ngEPSS 1.3%CVE-2021-21410HIGHOut-of-bounds read in the 6LoWPAN implementationEPSS 1.2%CVE-2022-35926MEDIUMOut-of-bounds read in IPv6 neighbor solicitation in Contiki-NGEPSS 1.2%CVE-2021-21257HIGHOut-of-bounds write in RPL-Classic and RPL-LiteEPSS 1.1%CVE-2021-21280HIGHOut-of-bounds write when processing 6LoWPAN extension headersEPSS 1.1%CVE-2021-21282HIGHBuffer overflow in RPL source routing header processingEPSS 1.0%CVE-2021-21279HIGHInfinite loop in IPv6 neighbor solicitation processingEPSS 1.0%CVE-2021-21281HIGHBuffer overflow due to unvalidated TCP data offsetEPSS 0.9%CVE-2023-28116HIGHBuffer overflow in L2CAP due to misconfigured MTUEPSS 0.7%CVE-2022-36054MEDIUMOut-of-bounds write when decompressing 6LoWPAN payload in Contiki-NGEPSS 0.6%CVE-2023-31129HIGHContiki-NG missing NULL pointer check in IPv6 neighbor discoveryEPSS 0.6%CVE-2023-30546CRITICALContiki-NG has off-by-one error in Antelope DBMSEPSS 0.6%CVE-2024-47181HIGHUnaligned memory access in RPL option processing in Contiki-NGEPSS 0.6%CVE-2022-36052MEDIUMOut-of-bounds read when decompressing UDP headerEPSS 0.5%CVE-2022-36053MEDIUMOut-of-bounds read in the uIP buffer moduleEPSS 0.5%CVE-2023-29001HIGHUncontrolled recursion due to insufficient validation of the IPv6 source routing header in Contiki-NGEPSS 0.5%CVE-2026-5855HIGHContiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in lwm2m_tlv_readEPSS 0.5%CVE-2026-5857CRITICALContiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP SegmentsEPSS 0.5%CVE-2023-50926HIGHUnvalidated DIO prefix info length in RPL-Lite in Contiki-NGEPSS 0.5%