PT-2023-3146 · Riot-Os · Riot-Os

Scepticz

+1

·

Publicado

2023-05-30

·

Atualizado

2023-06-06

·

CVE-2023-33974

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions RIOT-OS versions 2023.01 and prior
Description The issue is related to a 6LoWPAN frame handler in the RIOT operating system kernel, which is connected to pointer dereference errors. An attacker can exploit this issue by sending multiple crafted frames to the device, triggering a race condition that leads to an invalid memory access and results in a denial of service.
Recommendations For versions 2023.01 and prior, update to a version that includes the patch from pull request 19679 to resolve the issue. As a temporary workaround, consider restricting access to the network stack to minimize the risk of exploitation.

Exploit

Correção

NULL Pointer Dereference

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03245
BDU:2023-03246
CVE-2023-33974
GHSA-8M3W-MPHF-WXM8

Produtos afetados

Riot-Os