CVE-2020-13988Integer Overflow or Wraparound in Contiki-ng

Severity
7.5HIGHNVD
EPSS
0.2%
top 58.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateJul 27

Description

An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsing TCP MSS options of IPv4 network packets in uip_process in net/ipv4/uip.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/open-iscsi< open-iscsi 2.1.3-1 (bookworm)
Debianopen-iscsi_project/open-iscsi< 2.1.3-1+3
Ubuntuopen-iscsi_project/open-iscsi< 2.0.874-7.1ubuntu6.4+2

🔴Vulnerability Details

3
OSV
open-iscsi vulnerabilities2023-07-27
GHSA
GHSA-cx9v-96cj-78q9: An issue was discovered in Contiki through 32022-05-24
OSV
CVE-2020-13988: An issue was discovered in Contiki through 32020-12-11

📋Vendor Advisories

5
Ubuntu
Open-iSCSI vulnerabilities2023-07-27
CISA ICS
Siemens Embedded TCP/IP Stack Vulnerabilities–AMNESIA:33 (Update C)2021-03-09
Red Hat
Open-iSCSI: counter wraparound resulting in infinite loop2020-12-09
CISA ICS
Multiple Embedded TCP/IP Stacks2020-12-09
Debian
CVE-2020-13988: open-iscsi - An issue was discovered in Contiki through 3.0. An Integer Overflow exists in th...2020

🕵️Threat Intelligence

1
Tenable
AMNESIA:33: Researchers Disclose 33 Vulnerabilities Across Four Open Source TCP/IP Libraries2020-12-09