PT-2024-29281 · Unknown · Contiki-Ng

Owen Cochell

·

Published

2024-11-27

·

Updated

2024-11-27

·

CVE-2024-41126

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contiki-NG (affected versions not specified)
Description An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contiki-NG operating system with SNMP enabled. The issue exists in the os/net/app-layer/snmp/snmp-message.c module, specifically in the snmp message decode function, which fails to check the boundary of the message buffer when reading a byte from it immediately after decoding an object identifier (OID). The SNMP module is disabled in the default Contiki-NG configuration.
Recommendations To resolve the issue, users are advised to either apply the patch manually from Contiki-NG pull request 2937 or wait for the next release. As a temporary workaround, consider disabling the SNMP module in the Contiki-NG build configuration.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-41126
GHSA-444J-93J3-5GJ4

Affected Products

Contiki-Ng