PT-2023-3147 · Riot-Os · Riot-Os
Diff-Fusion
·
Published
2023-05-30
·
Updated
2023-06-06
·
CVE-2023-33973
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
RIOT-OS versions 2023.01 and prior
Description
The issue is related to the processing of 6LoWPAN frames in the network stack of RIOT-OS, an operating system for Internet of Things (IoT) devices. An attacker can send a crafted frame that, when forwarded by the device, causes a NULL pointer dereference during packet encoding, leading to a denial of service as the device crashes. There are no known workarounds for this issue.
Recommendations
For versions 2023.01 and prior, apply the patch available at pull request 19678 to resolve the issue. As a temporary workaround, consider restricting the ability of the device to forward crafted 6LoWPAN frames until the patch is applied.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Riot-Os