CVE-2021-21281 is a critical buffer overflow vulnerability affecting Contiki-NG versions prior to 4.6, an open-source operating system for IoT devices. An unvalidated data offset in TCP packets allows a remote attacker to trigger the overflow after a TCP socket is established. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a high risk of complete compromise (confidentiality, integrity, availability) with no user interaction required. While no public exploit code or active exploitation has been observed, and community discussion is minimal, users should update to Contiki-NG 4.6 or apply the provided patch immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.6CPE matchmatch criteria | cpe:2.3:o:contiki-ng:contiki-ng:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.