CVE-2020-12141

An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentially disclose information via crafted SNMP packets to snmp_ber_decode_string_len_buffer in os/net/app-layer/snmp/snmp-ber.c.
Configurations

Configuration 1 (hide)

cpe:2.3:o:contiki-ng:contiki-ng:*:*:*:*:*:*:*:*

History

22 Oct 2021, 19:09

Type Values Removed Values Added
References (MISC) https://twitter.com/ScepticCtf - (MISC) https://twitter.com/ScepticCtf - Third Party Advisory
References (MISC) https://github.com/contiki-ng/contiki-ng/pull/1355 - (MISC) https://github.com/contiki-ng/contiki-ng/pull/1355 - Patch, Third Party Advisory
References (MISC) https://github.com/contiki-ng/contiki-ng/commit/12c824386ab60de757de5001974d73b32e19ad71#diff-32367fad664c6118fd5dda77cdf38eedc006cdd7544eca5bbeebe0b99653f8a0 - (MISC) https://github.com/contiki-ng/contiki-ng/commit/12c824386ab60de757de5001974d73b32e19ad71#diff-32367fad664c6118fd5dda77cdf38eedc006cdd7544eca5bbeebe0b99653f8a0 - Patch, Third Party Advisory
CPE cpe:2.3:o:contiki-ng:contiki-ng:*:*:*:*:*:*:*:*
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : 6.4
v3 : 9.1

19 Oct 2021, 17:00

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-19 16:15

Updated : 2024-02-04 22:08


NVD link : CVE-2020-12141

Mitre link : CVE-2020-12141

CVE.ORG link : CVE-2020-12141


JSON object : View

Products Affected

contiki-ng

  • contiki-ng
CWE
CWE-125

Out-of-bounds Read