Vulnerabilidades en contiki-ng
32 resultadosAnálisis Vexday
Contiki-NG apresenta 29 vulnerabilidades catalogadas, mas nenhuma sob exploração ativa conhecida (KEV=0), reduzindo significativamente o risco imediato. A fraqueza dominante é leitura fora dos limites (CWE-125), com apenas 1 vulnerabilidade crítica, e nenhuma publicação nos últimos 90 dias indica que o risco não é contemporâneo. O perfil sugere exposure controlado, adequado para ambientes que já mitigaram as falhas mais graves.
CVE-2022-35927HIGHUnverified DIO prefix info lengths in RPL-Classic in Contiki-NGEPSS 2.0%CVE-2021-32771HIGHBuffer overflow in contiki-ngEPSS 1.3%CVE-2021-21410HIGHOut-of-bounds read in the 6LoWPAN implementationEPSS 1.2%CVE-2022-35926MEDIUMOut-of-bounds read in IPv6 neighbor solicitation in Contiki-NGEPSS 1.2%CVE-2021-21257HIGHOut-of-bounds write in RPL-Classic and RPL-LiteEPSS 1.1%CVE-2021-21280HIGHOut-of-bounds write when processing 6LoWPAN extension headersEPSS 1.1%CVE-2021-21282HIGHBuffer overflow in RPL source routing header processingEPSS 1.0%CVE-2021-21279HIGHInfinite loop in IPv6 neighbor solicitation processingEPSS 1.0%CVE-2021-21281HIGHBuffer overflow due to unvalidated TCP data offsetEPSS 0.9%CVE-2023-28116HIGHBuffer overflow in L2CAP due to misconfigured MTUEPSS 0.7%CVE-2022-36054MEDIUMOut-of-bounds write when decompressing 6LoWPAN payload in Contiki-NGEPSS 0.6%CVE-2023-31129HIGHContiki-NG missing NULL pointer check in IPv6 neighbor discoveryEPSS 0.6%CVE-2023-30546CRITICALContiki-NG has off-by-one error in Antelope DBMSEPSS 0.6%CVE-2024-47181HIGHUnaligned memory access in RPL option processing in Contiki-NGEPSS 0.6%CVE-2022-36052MEDIUMOut-of-bounds read when decompressing UDP headerEPSS 0.5%CVE-2022-36053MEDIUMOut-of-bounds read in the uIP buffer moduleEPSS 0.5%CVE-2023-29001HIGHUncontrolled recursion due to insufficient validation of the IPv6 source routing header in Contiki-NGEPSS 0.5%CVE-2026-5855HIGHContiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in lwm2m_tlv_readEPSS 0.5%CVE-2026-5857CRITICALContiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP SegmentsEPSS 0.5%CVE-2023-50926HIGHUnvalidated DIO prefix info length in RPL-Lite in Contiki-NGEPSS 0.5%