CVE-2021-38387
HIGHCVSS 7.5/10EPSS 0.96%
Last modified
CVE-2021-38387 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and waiting forever, which may cause excessive CPU consumption.. EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and waiting forever, which may cause excessive CPU consumption.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Contiki-Os | Contiki | 3.0 |
References
- https://github.com/contiki-os/contiki/issues/2688Third Party Advisory
- https://github.com/contiki-os/contiki/issues/2688Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-38387?
In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and waiting forever, which may cause excessive CPU consumption.
How severe is CVE-2021-38387?
CVE-2021-38387 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.96% probability of exploitation in the next 30 days.
How do I fix CVE-2021-38387?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-38381Live555 through 1.08 does not handle MPEG-1 or 2 files prope…6.5
- CVE-2021-38382Live555 through 1.08 does not handle Matroska and Ogg files …6.5
- CVE-2021-38383OwnTone (aka owntone-server) through 28.1 has a use-after-fr…9.8
- CVE-2021-38384Serverless Offline 8.0.0 returns a 403 HTTP status code for …9.8
- CVE-2021-38385Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the re…7.5
- CVE-2021-38386In Contiki 3.0, a buffer overflow in the Telnet service allo…7.5
- CVE-2021-38388Central Dogma allows privilege escalation with mirroring to …8.8
- CVE-2021-38389Advantech WebAccess versions 9.02 and prior are vulnerable t…9.8
- CVE-2021-3839A flaw was found in the vhost library in DPDK. Function vhos…7.5
- CVE-2021-38390A Blind SQL injection vulnerability exists in the /DataHandl…9.8
- CVE-2021-38391A Blind SQL injection vulnerability exists in the /DataHandl…9.8
- CVE-2021-38392A skilled attacker with physical access to the affected devi…7.6
Are you affected by CVE-2021-38387?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
