Contiki-NG是一套用于下一代IoT(物联网)设备的开源跨平台操作系统。 Contiki-NG 存在缓冲区错误漏洞,该漏洞源于在4.6及以上版本的设备的6LoWPAN报文会触发读越界。攻击者可利用该漏洞构造一个压缩的6LoWPAN包,它将读取比包缓冲区中可用的字节更多的字节。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| contiki-ng | contiki-ng | <= 4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-21280 | 8.6 HIGH | Out-of-bounds write when processing 6LoWPAN extension headers |
| CVE-2021-21282 | 8.6 HIGH | Buffer overflow in RPL source routing header processing |
| CVE-2021-21257 | 8.2 HIGH | Out-of-bounds write in RPL-Classic and RPL-Lite |
| CVE-2021-21279 | 7.5 HIGH | Infinite loop in IPv6 neighbor solicitation processing |
| CVE-2021-21281 | 7.0 HIGH | Buffer overflow due to unvalidated TCP data offset |
No comments yet