ICSA-20-343-01: Contiki os vulnerability
Affected Software
8 affected components
Multiple (open source) uIP-Contiki-OS (end-of-life [EOL]), Version 3.0 and prior
Multiple (open source) uIP-Contiki-NG, Version 4.5 and prior
Multiple (open source) uIP (EOL), Version 1.0 and prior
Multiple (open source) open-iscsi, Version 2.1.12 and prior
Multiple (open source) picoTCP-NG, Version 1.7.0 and prior
Multiple (open source) picoTCP (EOL), Version 1.7.0 and prior
Multiple (open source) FNET, Version 4.6.3
Multiple (open source) Nut/Net, Version 5.1 and prior
Event History
Feb 27, 2025
Advisory Published
02:24 PM
Frequently Asked Questions
1
What is the severity of ICSA-20-343-01?
The severity of ICSA-20-343-01 is classified as high due to the potential for remote code execution vulnerabilities.
2
How do I fix ICSA-20-343-01?
To mitigate ICSA-20-343-01, users should upgrade to the latest versions of the affected software or implement security measures such as network segmentation.
3
What systems are affected by ICSA-20-343-01?
ICSA-20-343-01 impacts multiple open-source software components including uIP-Contiki-OS, open-iscsi, and picoTCP due to their outdated versions.
4
Are there known exploits for ICSA-20-343-01?
Yes, there are known exploits related to ICSA-20-343-01 that could potentially be leveraged by attackers.
5
Is there a timeline for supporting ICSA-20-343-01?
As many of the affected software components are end-of-life, there may be limited support and users are encouraged to migrate to supported alternatives.