← Vulnerability feed

Vulnerability record · CVE-2020-24336 · published 11 December 2020

CVE-2020-24336: Contiki and Contiki-NG DNS64 parser buffer overflow via unchecked address length

Contiki Ng · Contiki Ng

Contiki through 3.0 and Contiki-NG through 4.5 fail to validate the length of an address in Type A domain name answers parsed by ip64-dns64.c. Copying an address of arbitrary length overflows a buffer, and the bug is reachable whenever NAT64 is enabled. Because the parser handles network-supplied DNS data, the flaw exposes NAT64-enabled devices to remote memory corruption.

9.8 CVSS 3.1 Critical EPSS 59% · top 0.9% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 7.5
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the answer's length is sane. Therefore, when copying an address of an arbitrary length, a buffer overflow can occur. This bug can be exploited whenever NAT64 is enabled.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and high EPSS probability make this a critical remote memory-corruption flaw for NAT64-enabled devices.

What it is

Contiki through 3.0 and Contiki-NG through 4.5 fail to validate the length of an address in Type A domain name answers parsed by ip64-dns64.c. Copying an address of arbitrary length overflows a buffer, and the bug is reachable whenever NAT64 is enabled. Because the parser handles network-supplied DNS data, the flaw exposes NAT64-enabled devices to remote memory corruption.

Impact

An attacker can corrupt memory in the DNS64 parsing path, which can lead to a crash or potentially code execution on the affected device. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network through DNS answers processed by the NAT64/DNS64 component; the CVSS vector shows no privileges and no user interaction required. The only stated precondition is that NAT64 is enabled on the target.

Exploitation

Not listed in CISA KEV and no ransomware use is documented; EPSS gives a 30-day probability of 0.59089 (99th percentile), and references are only third-party and US government advisories with no exploit tag.

What to do

  • Apply the vendor fixes for Contiki and Contiki-NG that address the ip64-dns64.c length validation; upgrade past the affected versions once patches are available.
  • If NAT64/DNS64 is not required, disable it to remove the vulnerable parsing path.
  • Restrict which DNS servers and networks can send DNS answers to NAT64-enabled devices, and filter malformed or oversized DNS responses at the network boundary.
  • Segment or isolate NAT64-enabled embedded devices so a compromise cannot spread to other network segments.

Detection

  • Monitor device logs and crash dumps for faults in the DNS64/NAT64 address parsing path.
  • Inspect DNS traffic to NAT64-enabled devices for Type A answers with abnormal or oversized address lengths.
  • Watch for unexpected device reboots, watchdog resets or memory corruption symptoms on NAT64-enabled Contiki/Contiki-NG devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 Third Party AdvisoryUS Government Resource
https://www.kb.cert.org/vuls/id/815128 Third Party AdvisoryUS Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 Third Party AdvisoryUS Government Resource
https://www.kb.cert.org/vuls/id/815128 Third Party AdvisoryUS Government Resource

Track CVE-2020-24336 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2018-19417Contiki-ng memory buffer overflow vulnerabilityAn issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a varia…EPSS 5.7%9.8CVE-2023-31129Contiki-ng null pointer dereference vulnerabilityThe Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message handling code for IPv6 router so…EPSS 0.64%9.8CVE-2023-28116Contiki-ng classic buffer overflow vulnerabilityContiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write…EPSS 0.69%9.8CVE-2022-35927Contiki-ng classic buffer overflow vulnerabilityContiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol implementation in the Contiki-NG o…EPSS 2.1%9.8CVE-2021-21280Contiki-ng out-of-bounds write vulnerabilityContiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bounds write in versi…EPSS 1.1%9.8CVE-2021-21281Contiki-ng classic buffer overflow vulnerabilityContiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG ve…EPSS 0.92%9.8CVE-2021-21282Contiki-ng classic buffer overflow vulnerabilityContiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, buffer overflow can be trigge…EPSS 0.99%9.8CVE-2020-14934Contiki-ng out-of-bounds write vulnerabilityBuffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. The function parsing the received SNMP request does not verify the…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2020-24336), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.