Altran's vulnerability footprint concentrates in the PicoTCP embedded networking stack, a modestly represented but notably positioned TCP/IP implementation targeting resource-constrained systems. The recurring vulnerabilities skew strongly toward critical severity and cluster around memory-safety and control-flow weaknesses—out-of-bounds reads and writes, integer overflows, double-free conditions, and infinite loops—that are characteristic of low-level network packet processing in C. Defenders deploying or maintaining systems that embed this stack should prioritize patch assessment; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Altran over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24338CRITICAL An issue was discovered in picoTCP through 1.7.0. The DNS domain name record decompression functionality in pico_dns_decompress_name() in pico_dns_common.c does not validate the co | Dec 11, 2020 | 9.8 | 48 | NO | NO |
CVE-2021-33304CRITICAL Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitra | Feb 15, 2023 | 9.8 | 31 | NO | NO |
CVE-2020-17441CRITICAL An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 payload length field is equal to the actual size of the payloa | Dec 11, 2020 | 9.1 | 31 | NO | NO |
CVE-2017-1000210CRITICAL picoTCP (versions 1.7.0 - 1.5.0) is vulnerable to stack buffer overflow resulting in code execution or denial of service attack | Nov 17, 2017 | 9.8 | 31 | NO | NO |
CVE-2020-24341CRITICAL An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The TCP input data processing function in pico_tcp.c does not validate the length of incoming TCP packets, which le | Dec 11, 2020 | 9.1 | 29 | NO | NO |
CVE-2020-17444HIGH An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv6 extension headers are valid) doesn't check whether the hea | Dec 11, 2020 | 7.5 | 26 | NO | NO |
CVE-2023-30463HIGH Altran picoTCP through 1.7.0 allows memory corruption (and subsequent denial of service) because of an integer overflow in pico_ipv6_alloc when processing large ICMPv6 packets. Thi | Apr 19, 2023 | 7.5 | 24 | NO | NO |
CVE-2020-24339HIGH An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The DNS domain name record decompression functionality in pico_dns_decompress_name() in pico_dns_common.c does not | Dec 11, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-24337HIGH An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. When an unsupported TCP option with zero length is provided in an incoming TCP packet, it is possible to cause a De | Dec 11, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-17443HIGH An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6 echo request packet's size is shorter than 8 bytes. If the s | Dec 11, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Altran.
Media articles that mention a CVE ID that affects a product developed by Altran — matched by CVE ID, not by vendor name.