Contiki OS is a lightweight operating system designed for embedded systems and Internet-of-Things devices with severely constrained resources, and the vulnerability disclosures associated with it reflect the challenges of securing networked firmware in that domain. The vendor's footprint remains modestly represented in the broader vulnerability landscape, though its prominence within the IoT and embedded systems ecosystem is more pronounced given the widespread deployment of Contiki-based devices in sensor networks and low-power wireless applications. The observed vulnerability patterns do not cluster around a single dominant weakness class, reflecting the diverse attack surface spanning network protocols, memory management, and device-specific configurations that characterize an OS serving heterogeneous hardware platforms. Defenders operating Contiki-based deployments should prioritize inventory of affected devices and firmware versions, as patching embedded systems often requires coordination across hardware vendors and deployment contexts rather than straightforward updates. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contiki Os over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24336CRITICAL An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the | Dec 11, 2020 | 9.8 | 62 | NO | NO |
CVE-2020-25112CRITICAL An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths. This leads to Denial-of-Service and potential Rem | Dec 11, 2020 | 9.8 | 43 | NO | NO |
CVE-2020-25111CRITICAL An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This leads to Denial-of-Service and potential Remote Co | Dec 11, 2020 | 9.8 | 40 | NO | NO |
CVE-2020-17438CRITICAL An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incomi | Dec 11, 2020 | 9.8 | 37 | NO | NO |
CVE-2019-8359CRITICAL An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. An out of bounds write is present in the data section during 6LoWPAN fragment re-assembly in the face of | Apr 23, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-17437HIGH An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, t | Dec 11, 2020 | 8.2 | 26 | NO | NO |
CVE-2021-40523HIGH In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to give the WILL/WONT or DO/DONT response for DO and | Sep 5, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-24334HIGH The code that processes DNS responses in uIP through 1.0, as used in Contiki and Contiki-NG, does not check whether the number of responses specified in the DNS packet header corre | Dec 11, 2020 | 8.2 | 25 | NO | NO |
CVE-2020-17439HIGH An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that the incoming DNS replies match outgo | Dec 11, 2020 | 8.3 | 25 | NO | NO |
CVE-2020-13987HIGH An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_ | Dec 11, 2020 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contiki Os.
Media articles that mention a CVE ID that affects a product developed by Contiki Os — matched by CVE ID, not by vendor name.