AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-17438

CRITICAL · CVSS 9.8 EPSS 18.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-12-11 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 18.5% probability of exploitation in the next 30 days. It may lead to a denial-of-service condition.

CVE
CVE-2020-17438
Severity
CRITICAL
CVSS
9.8
EPSS
18.54%

Original NVD Description

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incoming packet specified in its IP header, as well as the fragmentation offset value specified in the IP header. By crafting a packet with specific values of the IP header length and the fragmentation offset, attackers can write into the .bss section of the program (past the statically allocated buffer that is used for storing the fragmented data) and cause a denial of service in uip_reass() in uip.c, or possibly execute arbitrary code on some target architectures.

Related CVEs

Other vulnerabilities affecting the same vendor(s)