Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-29001— Uncontrolled recursion due to insufficient validation of the IPv6 source routing header in Contiki-NG

Quick assessment

Affected
contiki-ng contiki-ng
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contiki-NG是Contiki-NG开源的一个适用于物联网中资源受限设备的操作系统。 Contiki-NG 4.9及之前版本存在安全漏洞,该漏洞源于缺少对下一跳地址的有效验证,可能产生非受控递归,使得攻击者能够通过发送特定IPv6数据包触发深层嵌套的递归调用,从而造成栈溢出。

AI Predicted 7.5 Difficulty: Easy EPSS 0.56% · P44

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-29001

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Uncontrolled recursion due to insufficient validation of the IPv6 source routing header in Contiki-NG
Source: CVE Program / CVE List V5
Vulnerability Description
Contiki-NG is an open-source, cross-platform operating system for IoT devices. The Contiki-NG operating system processes source routing headers (SRH) in its two alternative RPL protocol implementations. The IPv6 implementation uses the results of this processing to determine whether an incoming packet should be forwarded to another host. Because of missing validation of the resulting next-hop address, an uncontrolled recursion may occur in the tcpip_ipv6_output function in the os/net/ipv6/tcpip.c module when receiving a packet with a next-hop address that is a local address. Attackers that have the possibility to send IPv6 packets to the Contiki-NG host can therefore trigger deeply nested recursive calls, which can cause a stack overflow. The vulnerability has not been patched in the current release of Contiki-NG, but is expected to be patched in the next release. The problem can be fixed by applying the patch in Contiki-NG pull request #2264. Users are advised to either apply the patch manually or to wait for the next release. There are no known workarounds for this vulnerability.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的递归
Source: CVE Program / CVE List V5
Vulnerability Title
Contiki-NG 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Contiki-NG是Contiki-NG开源的一个适用于物联网中资源受限设备的操作系统。 Contiki-NG 4.9及之前版本存在安全漏洞,该漏洞源于缺少对下一跳地址的有效验证,可能产生非受控递归,使得攻击者能够通过发送特定IPv6数据包触发深层嵌套的递归调用,从而造成栈溢出。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
contiki-ng contiki-ng <= 4.9 -

II. Public POCs for CVE-2023-29001

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-29001

请登录查看更多情报信息。

Patches & Fixes for CVE-2023-29001 (1)

Same Patch Batch · contiki-ng · 2024-11-27 · 4 CVEs total

CVE-2024-41125 8.4 HIGH Out-of-bounds read in SNMP when decoding a string in Contiki-NG
CVE-2024-41126 8.4 HIGH Out-of-bounds read when decoding SNMP messages in Contiki-NG
CVE-2024-47181 7.5 HIGH Unaligned memory access in RPL option processing in Contiki-NG

IV. Related Vulnerabilities

V. Comments for CVE-2023-29001

No comments yet


Leave a comment