CVE-2021-38311
Last modified
CVE-2021-38311 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Contiki 3.0, potential nonterminating acknowledgment loops exist in the Telnet service. When the negotiated options are already disabled, servers still respond to DONT and WONT requests with WONT or DONT commands, which may lead to infinite acknowledgment loops, denial of service, and excessive CPU consumption.. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
In Contiki 3.0, potential nonterminating acknowledgment loops exist in the Telnet service. When the negotiated options are already disabled, servers still respond to DONT and WONT requests with WONT or DONT commands, which may lead to infinite acknowledgment loops, denial of service, and excessive CPU consumption.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Contiki-Os | Contiki | 3.0 |
References
- https://github.com/contiki-os/contiki/issues/2685Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/contiki-os/contiki/issues/2685Exploit, Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-38311?
How severe is CVE-2021-38311?
How do I fix CVE-2021-38311?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-38302The Newsletter extension through 4.0.0 for TYPO3 allows SQL …9.8
- CVE-2021-38303A SQL injection vulnerability exists in Sureline SUREedge Mi…9.8
- CVE-2021-38304Improper input validation in the National Instruments NI-PAL…7.8
- CVE-2021-3830523andMe Yamale before 3.0.8 allows remote attackers to execu…7.8
- CVE-2021-38306Network Attached Storage on LG N1T1*** 10124 devices allows …9.8
- CVE-2021-3831gnuboard5 is vulnerable to Improper Neutralization of Input …6.1
- CVE-2021-38312The Gutenberg Template Library & Redux Framework plugin <= 4…6.5
- CVE-2021-38314The Gutenberg Template Library & Redux Framework plugin <= 4…5.3
- CVE-2021-38315The SP Project & Document Manager WordPress plugin is vulner…6.1
- CVE-2021-38316The WP Academic People List WordPress plugin is vulnerable t…6.1
- CVE-2021-38317The Konnichiwa! Membership WordPress plugin is vulnerable to…6.1
- CVE-2021-38318The 3D Cover Carousel WordPress plugin is vulnerable to Refl…6.1
Are you affected by CVE-2021-38311?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
