Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Chrysn

#17493of 53,624
15.3Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2023-19805
9.8
2023-04-24
Riot-Os · Riot-Os · CVE-2023-24823
**Name of the Vulnerable Software and Affected Versions** RIOT-OS versions prior to 2022.10 **Description** The issue arises from a type confusion between IPv6 extension headers and a UDP header while encoding a 6LoWPAN IPHC header in the network stack. This type confusion results in an out of bounds write in the packet buffer, potentially leading to denial of service by corrupting other packets and the allocator metadata. Furthermore, an attacker can manipulate the allocator metadata to write data to arbitrary locations, thus enabling the execution of arbitrary code. **Recommendations** For versions prior to 2022.10, update to version 2022.10 to resolve the issue. As a temporary workaround for versions prior to 2022.10, apply the patches manually.
PT-2021-23061
5.5
2021-09-15
Riot-Os · Riot-Os · CVE-2021-41061
**Name of the Vulnerable Software and Affected Versions** RIOT-OS version 2021.01 **Description** The issue allows attackers to break encryption by triggering reboots due to nonce reuse in 802.15.4 encryption in the ieee820154 security component. **Recommendations** For RIOT-OS version 2021.01, consider disabling the ieee820154 security component until a patch is available to prevent nonce reuse and potential encryption breaks.