← Back to CVEs
CVE-2019-1000006
CRITICAL9.8
Description
RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in sock_dns, an implementation of the DNS protocol utilizing the RIOT sock API that can result in Remote code executing. This attack appears to be exploitable via network connectivity.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published2/4/2019
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
riot-os:riot
Weaknesses (CWE)
CWE-787
References
https://github.com/RIOT-OS/RIOT/issues/10739(cve@mitre.org)
https://github.com/RIOT-OS/RIOT/issues/10739(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.