Contiki-NG是一套用于下一代IoT(物联网)设备的开源跨平台操作系统。 Contiki-NG 4.7及以前的版本存在安全漏洞,该漏洞源于攻击者在RPL-Classic实现中复制IPv6地址前缀时,可能会导致缓冲区溢出。触发该漏洞的前提是Contiki-NG系统必须加入RPL DODAG。在此之后,攻击者可以发送一个带有Target选项的DAO包(其中包含大于128位的前缀长度)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| contiki-ng | contiki-ng | < 4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-35927 | 8.1 HIGH | Unverified DIO prefix info lengths in RPL-Classic in Contiki-NG |
| CVE-2022-35926 | 5.9 MEDIUM | Out-of-bounds read in IPv6 neighbor solicitation in Contiki-NG |
No comments yet