Vulnerability Description
In Contiki 3.0, potential nonterminating acknowledgment loops exist in the Telnet service. When the negotiated options are already disabled, servers still respond to DONT and WONT requests with WONT or DONT commands, which may lead to infinite acknowledgment loops, denial of service, and excessive CPU consumption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Contiki-Os | Contiki | 3.0 |
Related Weaknesses (CWE)
References
- https://github.com/contiki-os/contiki/issues/2685ExploitIssue TrackingPatch
- https://github.com/contiki-os/contiki/issues/2685ExploitIssue TrackingPatch
FAQ
What is CVE-2021-38311?
CVE-2021-38311 is a vulnerability with a CVSS score of 7.5 (HIGH). In Contiki 3.0, potential nonterminating acknowledgment loops exist in the Telnet service. When the negotiated options are already disabled, servers still respond to DONT and WONT requests with WONT o...
How severe is CVE-2021-38311?
CVE-2021-38311 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38311?
Check the references section above for vendor advisories and patch information. Affected products include: Contiki-Os Contiki.