CVE-2021-40523

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/09/2021
Last modified:
10/09/2021

Description

In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to give the WILL/WONT or DO/DONT response for DO and WILL commands because of improper handling of exception condition, which leads to property violations and denial of service. Specifically, a server sometimes sends no response, because a fixed buffer space is available for all responses and that space may have been exhausted.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:contiki-os:contiki:3.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools