CVE-2021-21280
Last modified
CVE-2021-21280 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bounds write in versions of Contiki-NG prior to 4.6 when transmitting a 6LoWPAN packet with a chain of extension headers. EPSS estimates a 1.06% chance of exploitation in the next 30 days.
Description
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bounds write in versions of Contiki-NG prior to 4.6 when transmitting a 6LoWPAN packet with a chain of extension headers. Unfortunately, the written header is not checked to be within the available space, thereby making it possible to write outside the buffer. The problem has been patched in Contiki-NG 4.6. Users can apply the patch for this vulnerability out-of-band as a workaround.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Contiki-Ng | Contiki-Ng | < 4.6 |
References
- https://github.com/contiki-ng/contiki-ng/pull/1409Patch, Third Party Advisory
- https://github.com/contiki-ng/contiki-ng/security/advisories/GHSA-r768-hrhf-v592Exploit, Patch, Third Party Advisory
- https://github.com/contiki-ng/contiki-ng/pull/1409Patch, Third Party Advisory
- https://github.com/contiki-ng/contiki-ng/security/advisories/GHSA-r768-hrhf-v592Exploit, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21280?
How severe is CVE-2021-21280?
How do I fix CVE-2021-21280?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-21275The MediaWiki "Report" extension has a Cross-Site Request Fo…4.3
- CVE-2021-21276Polr is an open source URL shortener. in Polr before version…9.3
- CVE-2021-21277angular-expressions is "angular's nicest part extracted as a…8.8
- CVE-2021-21278RSSHub is an open source, easy to use, and extensible RSS fe…9.8
- CVE-2021-21279Contiki-NG is an open-source, cross-platform operating syste…7.5
- CVE-2021-2128Vulnerability in the Oracle VM VirtualBox product of Oracle …6.5
- CVE-2021-21281Contiki-NG is an open-source, cross-platform operating syste…9.8
- CVE-2021-21282Contiki-NG is an open-source, cross-platform operating syste…9.8
- CVE-2021-21283Flarum is an open source discussion platform for websites. T…5.4
- CVE-2021-21284In Docker before versions 9.03.15, 20.10.3 there is a vulner…6.8
- CVE-2021-21285In Docker before versions 9.03.15, 20.10.3 there is a vulner…6.5
- CVE-2021-21286AVideo Platform is an open-source Audio and Video platform. …8.8
Are you affected by CVE-2021-21280?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
