Vulnerabilidades em Contiki-NG
32 resultadosAnálise Vexday
Contiki-NG registra 3 vulnerabilidades na base Vexday, todas publicadas nos últimos 90 dias, com 1 classificada como crítica e nenhuma sob ataque ativo conhecido. A fraqueza dominante é leitura fora dos limites (CWE-125), típica de software embarcado, indicando risco recente que demanda atenção mas sem exploração ativa documentada no momento.
CVE-2023-50927HIGHInsufficient boundary checks for DIO and DAO messages in RPL-Lite in Contiki-NGEPSS 0.5%CVE-2023-34101HIGHContiki-NG vulnerable to out-of-bounds read when processing ICMP DAO inputEPSS 0.5%CVE-2023-34100HIGHOut-of-Bounds Read in contiki-ngEPSS 0.4%CVE-2023-48229HIGHOut-of-bounds write in the radio driver for Contiki-NG nRF platformsEPSS 0.4%CVE-2023-37281MEDIUMOut-of-bounds read during IPHC address decompressionEPSS 0.4%CVE-2023-37459MEDIUMOut-of-bounds read when processing a received IPv6 packetEPSS 0.4%CVE-2023-23609HIGHcontiki-ng BLE-L2CAP contains Improper size validation of L2CAP framesEPSS 0.4%CVE-2024-41126HIGHOut-of-bounds read when decoding SNMP messages in Contiki-NGEPSS 0.3%CVE-2024-41125HIGHOut-of-bounds read in SNMP when decoding a string in Contiki-NGEPSS 0.3%CVE-2026-5856HIGHContiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Traversal Before Transaction-ID ValidationEPSS 0.3%CVE-2022-41873MEDIUMOut-of-bounds read and write in BLE L2CAP moduleEPSS 0.2%CVE-2022-41972LOWContiki-NG contains NULL Pointer Dereference in BLE L2CAP moduleEPSS 0.2%