PT-2024-29281 · Unknown · Contiki-Ng
Owen Cochell
·
Published
2024-11-27
·
Updated
2024-11-27
·
CVE-2024-41126
CVSS v3.1
9.6
Critical
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contiki-NG (affected versions not specified)
Description
An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contiki-NG operating system with SNMP enabled. The issue exists in the os/net/app-layer/snmp/snmp-message.c module, specifically in the
snmp message decode function, which fails to check the boundary of the message buffer when reading a byte from it immediately after decoding an object identifier (OID). The SNMP module is disabled in the default Contiki-NG configuration.Recommendations
To resolve the issue, users are advised to either apply the patch manually from Contiki-NG pull request 2937 or wait for the next release.
As a temporary workaround, consider disabling the SNMP module in the Contiki-NG build configuration.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contiki-Ng