Contiki-NG是一套用于下一代IoT(物联网)设备的开源跨平台操作系统。 Contiki-NG 存在缓冲区错误漏洞,该漏洞源于在4.6之前的操作系统版本中的RPL- classic和RPL- lite实现不验证RPL源路由报头中的地址指针。攻击者可利用该漏洞通过注入到网络堆栈中的数据包导致超出范围的写操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| contiki-ng | contiki-ng | < 4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-21280 | 8.6 HIGH | Out-of-bounds write when processing 6LoWPAN extension headers |
| CVE-2021-21282 | 8.6 HIGH | Buffer overflow in RPL source routing header processing |
| CVE-2021-21410 | 8.2 HIGH | Out-of-bounds read in the 6LoWPAN implementation |
| CVE-2021-21279 | 7.5 HIGH | Infinite loop in IPv6 neighbor solicitation processing |
| CVE-2021-21281 | 7.0 HIGH | Buffer overflow due to unvalidated TCP data offset |
No comments yet