PT-2021-22100 · Contiki · Contiki
Jerrytesting
·
Published
2021-08-10
·
Updated
2021-08-17
·
CVE-2021-38386
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Contiki version 3.0
Description
The issue is related to a buffer overflow in the Telnet service, which can be exploited by remote attackers to cause a denial of service. This occurs because the
ls command is mishandled when a directory contains many files with long names.Recommendations
For Contiki version 3.0, consider disabling the Telnet service until a patch is available to prevent potential denial of service attacks. Restrict access to directories with many files to minimize the risk of exploitation. Avoid using the
ls command in the Telnet service for directories with long file names until the issue is resolved.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contiki