Vulnerability Description
In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to give the WILL/WONT or DO/DONT response for DO and WILL commands because of improper handling of exception condition, which leads to property violations and denial of service. Specifically, a server sometimes sends no response, because a fixed buffer space is available for all responses and that space may have been exhausted.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Contiki-Os | Contiki | 3.0 |
Related Weaknesses (CWE)
References
- https://github.com/contiki-os/contiki/issues/2686PatchThird Party Advisory
- https://github.com/contiki-os/contiki/issues/2686PatchThird Party Advisory
FAQ
What is CVE-2021-40523?
CVE-2021-40523 is a vulnerability with a CVSS score of 7.5 (HIGH). In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to give the WILL/WONT or DO/DONT response for DO and WILL commands becaus...
How severe is CVE-2021-40523?
CVE-2021-40523 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40523?
Check the references section above for vendor advisories and patch information. Affected products include: Contiki-Os Contiki.