RIOT-OS vulnerable to Out of Bounds write in routing with SRH
CVE-2023-24817

7.5HIGH

Key Information:

Vendor

Riot-os

Status
Vendor
CVE Published:
30 May 2023

What is CVE-2023-24817?

A vulnerability in the network stack of RIOT-OS prior to version 2023.04 allows an attacker to manipulate 6LoWPAN frame processing, potentially leading to an integer underflow and out-of-bounds access in the packet buffer. Successfully exploiting this issue can result in packet corruption and denial of service by disrupting the underlying memory management. Users are advised to update to version 2023.04 or implement a workaround by disabling SRH in the network stack to bolster security.

Affected Version(s)

RIOT < 2023.04

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.