📦 Contiki Ng

by Contiki Ng

🔍 What is Contiki Ng?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-30546

CRITICAL CVSS 9.8 Apr 26, 2023

An off-by-one buffer overflow vulnerability in Contiki-NG's Antelope database system allows memory corruption when merging strings in storage functions. This affects IoT devices running Contiki-NG 4.8...

CVE-2020-12141

CRITICAL CVSS 9.1 Oct 19, 2021

CVE-2020-12141 is an out-of-bounds read vulnerability in the SNMP stack of Contiki-NG, an operating system for IoT devices. Attackers can send crafted SNMP packets to cause denial of service and poten...

CVE-2020-24336

CRITICAL CVSS 9.8 Dec 11, 2020

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via buffer overflow in Contiki and Contiki-NG operating systems when NAT64 is enabled. The bug occurs wh...

CVE-2024-47181

HIGH CVSS 7.5 Nov 27, 2024

An unaligned memory access vulnerability in Contiki-NG's RPL implementations can cause system crashes when processing malformed IPv6 packets with odd padding. This affects IoT devices running Contiki-...

CVE-2024-41125

HIGH CVSS 8.3 Nov 27, 2024

CVE-2024-41125 is an out-of-bounds read vulnerability in Contiki-NG's SNMP module that could allow attackers to read one byte of memory beyond an allocated buffer. This affects IoT devices running Con...

CVE-2023-50927

HIGH CVSS 8.6 Feb 14, 2024

This vulnerability allows attackers to trigger out-of-bounds reads in the RPL-Lite implementation of the RPL protocol in Contiki-NG IoT operating systems. Attackers can exploit insufficient length con...

CVE-2023-48229

HIGH CVSS 7.0 Feb 14, 2024

An out-of-bounds write vulnerability in Contiki-NG's IEEE 802.15.4 radio driver allows attackers to write beyond allocated buffer boundaries when parsing malicious radio frames. This affects IoT devic...

CVE-2023-34101

HIGH CVSS 7.3 Jun 14, 2023

This vulnerability in Contiki-NG OS allows attackers to trigger out-of-bounds memory reads by sending specially crafted truncated ICMP DAO packets. IoT devices running Contiki-NG version 4.8 or earlie...

CVE-2023-34100

HIGH CVSS 7.3 Jun 9, 2023

This CVE describes a buffer overflow vulnerability in Contiki-NG's TCP MSS option parsing for IPv6 packets. Attackers can trigger out-of-bounds memory reads by sending specially crafted packets, poten...

CVE-2020-12140

HIGH CVSS 8.8 Dec 7, 2021

This CVE describes a buffer overflow vulnerability in the BLE L2CAP implementation of Contiki-NG, an operating system for IoT devices. Attackers can send malicious Bluetooth Low Energy frames to execu...

CVE-2021-21257

HIGH CVSS 8.2 Jun 18, 2021

This vulnerability allows attackers to perform out-of-bounds memory writes by injecting specially crafted packets into Contiki-NG's RPL routing implementation. It affects IoT devices running Contiki-N...

CVE-2021-21280

HIGH CVSS 8.6 Jun 18, 2021

This vulnerability allows attackers to cause an out-of-bounds write in Contiki-NG IoT operating system when processing 6LoWPAN packets with extension header chains. This could lead to memory corruptio...

CVE-2021-21410

HIGH CVSS 8.2 Jun 18, 2021

CVE-2021-21410 is an out-of-bounds read vulnerability in Contiki-NG's 6LoWPAN packet processing that allows attackers to read beyond allocated memory boundaries. This affects IoT devices running Conti...

CVE-2021-21282

HIGH CVSS 8.6 Jun 18, 2021

CVE-2021-21282 is a buffer overflow vulnerability in Contiki-NG's RPL implementations when operating in source-routing mode. Attackers can exploit this by sending specially crafted input packets to po...