CVE-2020-12141: Critical severity naranjascontocados vulnerability
An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentially disclose information via crafted SNMP packets to snmpberdecodestringlenbuffer in os/net/app-layer/snmp/snmp-ber.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-12141?
CVE-2020-12141 is a vulnerability in the SNMP stack in Contiki-NG 4.4 and earlier that allows an attacker to cause a denial of service and potentially disclose information via crafted SNMP packets.
What is the severity of CVE-2020-12141?
The severity of CVE-2020-12141 is critical with a CVSS score of 9.1.
How can an attacker exploit CVE-2020-12141?
An attacker can exploit CVE-2020-12141 by sending crafted SNMP packets to snmp_ber_decode_string_len_buffer in os/net/app-layer/snmp/snmp-ber.c.
How can I fix CVE-2020-12141?
To fix CVE-2020-12141, it is recommended to update Contiki-NG to version 4.5 or later.
Is there any additional information about CVE-2020-12141?
Yes, you can find more information about CVE-2020-12141 in the references: [GitHub commit](https://github.com/contiki-ng/contiki-ng/commit/12c824386ab60de757de5001974d73b32e19ad71#diff-32367fad664c6118fd5dda77cdf38eedc006cdd7544eca5bbeebe0b99653f8a0), [GitHub pull request](https://github.com/contiki-ng/contiki-ng/pull/1355), [Twitter post](https://twitter.com/ScepticCtf).