CVE-2023-33973

CVSS V2 None CVSS V3 None
Description
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In versions 2023.01 and prior, an attacker can send a crafted frame which is forwarded by the device. During encoding of the packet a NULL pointer dereference occurs. This crashes the device leading to denial of service. A patch is available at pull request 19678. There are no known workarounds.
Overview
  • CVE ID
  • CVE-2023-33973
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-05-30T16:18:04.163Z
  • Last Modified Date
  • 2023-05-30T16:18:04.163Z
History
Created Old Value New Value Data Type Notes
2024-06-25 07:57:23 Added to TrackCVE