Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-28362

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contiki是一套用于IoT(物联网)设备的开源跨平台操作系统。 Contiki through 3.0 存在安全漏洞,该漏洞源于变量是容易整数下溢,可以构造一个无效的扩展头,会导致内存泄露问题,导致拒绝服务条件。

AI Predicted 5.3 Difficulty: Moderate EPSS 1.31% · P70

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-28362

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in Contiki through 3.0. When sending an ICMPv6 error message because of invalid extension header options in an incoming IPv6 packet, there is an attempt to remove the RPL extension headers. Because the packet length and the extension header length are unchecked (with respect to the available data) at this stage, and these variables are susceptible to integer underflow, it is possible to construct an invalid extension header that will cause memory corruption issues and lead to a Denial-of-Service condition. This is related to rpl-ext-header.c.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Contiki 数字错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Contiki是一套用于IoT(物联网)设备的开源跨平台操作系统。 Contiki through 3.0 存在安全漏洞,该漏洞源于变量是容易整数下溢,可以构造一个无效的扩展头,会导致内存泄露问题,导致拒绝服务条件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2021-28362

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-28362

请登录查看更多情报信息。

Vendor Advisories for CVE-2021-28362 (1)

Other References for CVE-2021-28362 (1)

Same Patch Batch · n/a · 2021-03-24 · 25 CVEs total

CVE-2020-36283 9.6 CRITICAL HID Global OMNIKEY 跨站请求伪造漏洞
CVE-2021-27315 Sourcecodesterk Doctor Appointment System SQL注入漏洞
CVE-2021-28967 Xavier Hahn vscode-matlab 默认配置问题漏洞
CVE-2021-29133 Alpine Linux 安全漏洞
CVE-2021-29025 Bitweaver 跨站脚本漏洞
CVE-2021-29026 Bitweaver 跨站脚本漏洞
CVE-2021-29027 Bitweaver 跨站脚本漏洞
CVE-2021-29028 Bitweaver 跨站脚本漏洞
CVE-2021-29029 Bitweaver 跨站脚本漏洞
CVE-2021-29030 Bitweaver 跨站脚本漏洞
CVE-2021-29031 Bitweaver 跨站脚本漏洞
CVE-2021-29032 Bitweaver 跨站脚本漏洞
CVE-2021-29033 Bitweaver 跨站脚本漏洞
CVE-2020-15809 SpinetiX SpinetiX 路径遍历漏洞
CVE-2021-27316 Sourcecodesterk Doctor Appointment System SQL注入漏洞
CVE-2021-27319 Sourcecodesterk Doctor Appointment System SQL注入漏洞
CVE-2021-27320 Sourcecodesterk Doctor Appointment System SQL注入漏洞
CVE-2021-29002 Plone 跨站脚本漏洞
CVE-2019-19349 Red Hat OpenShift Container Platform 安全漏洞
CVE-2019-19350 Red Hat OpenShift Container Platform 安全漏洞

Showing top 20 of 25 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-28362

No comments yet


Leave a comment