Vulnerability record · CVE-2020-24336 · published 11 December 2020
CVE-2020-24336: Contiki and Contiki-NG DNS64 parser buffer overflow via unchecked address length
Contiki Ng · Contiki Ng
Contiki through 3.0 and Contiki-NG through 4.5 fail to validate the length of an address in Type A domain name answers parsed by ip64-dns64.c. Copying an address of arbitrary length overflows a buffer, and the bug is reachable whenever NAT64 is enabled. Because the parser handles network-supplied DNS data, the flaw exposes NAT64-enabled devices to remote memory corruption.
Description
An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the answer's length is sane. Therefore, when copying an address of an arbitrary length, a buffer overflow can occur. This bug can be exploited whenever NAT64 is enabled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and high EPSS probability make this a critical remote memory-corruption flaw for NAT64-enabled devices.
What it is
Contiki through 3.0 and Contiki-NG through 4.5 fail to validate the length of an address in Type A domain name answers parsed by ip64-dns64.c. Copying an address of arbitrary length overflows a buffer, and the bug is reachable whenever NAT64 is enabled. Because the parser handles network-supplied DNS data, the flaw exposes NAT64-enabled devices to remote memory corruption.
Impact
An attacker can corrupt memory in the DNS64 parsing path, which can lead to a crash or potentially code execution on the affected device. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through DNS answers processed by the NAT64/DNS64 component; the CVSS vector shows no privileges and no user interaction required. The only stated precondition is that NAT64 is enabled on the target.
Exploitation
Not listed in CISA KEV and no ransomware use is documented; EPSS gives a 30-day probability of 0.59089 (99th percentile), and references are only third-party and US government advisories with no exploit tag.
What to do
- Apply the vendor fixes for Contiki and Contiki-NG that address the ip64-dns64.c length validation; upgrade past the affected versions once patches are available.
- If NAT64/DNS64 is not required, disable it to remove the vulnerable parsing path.
- Restrict which DNS servers and networks can send DNS answers to NAT64-enabled devices, and filter malformed or oversized DNS responses at the network boundary.
- Segment or isolate NAT64-enabled embedded devices so a compromise cannot spread to other network segments.
Detection
- Monitor device logs and crash dumps for faults in the DNS64/NAT64 address parsing path.
- Inspect DNS traffic to NAT64-enabled devices for Type A answers with abnormal or oversized address lengths.
- Watch for unexpected device reboots, watchdog resets or memory corruption symptoms on NAT64-enabled Contiki/Contiki-NG devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 | Third Party AdvisoryUS Government Resource |
| https://www.kb.cert.org/vuls/id/815128 | Third Party AdvisoryUS Government Resource |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 | Third Party AdvisoryUS Government Resource |
| https://www.kb.cert.org/vuls/id/815128 | Third Party AdvisoryUS Government Resource |
Track CVE-2020-24336 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-24336), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.