CVE-2022-35927 is a critical buffer overflow vulnerability in the RPL-Classic routing protocol of Contiki-NG, an open-source operating system for IoT devices. Specifically, unvalidated length parameters in incoming DODAG Information Option (DIO) control messages can lead to a buffer overflow when copying prefixes. This affects Contiki-NG versions prior to 4.7, impacting devices that can receive RPL DIO messages from external sources. With a CVSS score of 9.8 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity, requiring no user interaction or privileges, and can lead to complete compromise of confidentiality, integrity, and availability. The EPSS score is low, indicating a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, or entries in ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.7CPE matchmatch criteria | cpe:2.3:o:contiki-ng:contiki-ng:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.