Uip is a compact, single-product embedded TCP/IP stack implementation with a surprising concentration of critical-severity vulnerabilities relative to its narrow footprint. Its exposure recurs around memory-safety issues—out-of-bounds reads and writes, improper input validation—that are characteristic of C-based network protocol handlers processing untrusted data from the network edge. Defenders should prioritize inventory of devices and applications embedding this stack and treat disclosed flaws as high-risk; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uip Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-17438CRITICAL An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incomi | Dec 11, 2020 | 9.8 | 37 | NO | NO |
CVE-2020-17437HIGH An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, t | Dec 11, 2020 | 8.2 | 26 | NO | NO |
CVE-2020-24334HIGH The code that processes DNS responses in uIP through 1.0, as used in Contiki and Contiki-NG, does not check whether the number of responses specified in the DNS packet header corre | Dec 11, 2020 | 8.2 | 25 | NO | NO |
CVE-2020-17439HIGH An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that the incoming DNS replies match outgo | Dec 11, 2020 | 8.3 | 25 | NO | NO |
CVE-2020-13987HIGH An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_ | Dec 11, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-24335HIGH An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, allowing an attacker to corrupt memory with crafted DNS pack | Feb 2, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-17440HIGH An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that domain names present in the DNS resp | Dec 11, 2020 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uip Project.
Media articles that mention a CVE ID that affects a product developed by Uip Project — matched by CVE ID, not by vendor name.