HIGH🇬🇧 English

CVE-2021-38387

CVSS 7.5v3.1pub. 2021-08-10upd. 2024-11-21

In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and waiting forever, which may cause excessive CPU consumption.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Contiki Os Contiki

    OS
    Contiki-Os
    3.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2020-24336CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w parsowaniu DNS w Contiki i Contiki-NG (NAT64)

CVE-2020-17438CRITICAL9.8PL ✓ten sam produkt

RCE/DoS w uIP 1.0 — błąd składania fragmentów pakietów IP

CVE-2019-8359CRITICAL9.8PL ✓ten sam produkt

Out-of-bounds write w re-składaniu fragmentów 6LoWPAN w Contiki/Contiki-NG

CVE-2021-40523HIGH7.5ten sam produkt

In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the...

CVE-2021-38386HIGH7.5ten sam produkt

In Contiki 3.0, a buffer overflow in the Telnet service allows remote attackers to cause a denial of service b...