CVE-2020-24335: Uip Project Uip

High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.

An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, allowing an attacker to corrupt memory with crafted DNS packets.

Affected products

Published 2021-02-02. Last modified 2026-06-17.