CVE-2020-8916

MEDIUM

Openthread Wpantund < 2020-05-28 - Memory Leak

Title source: rule

Description

A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the control driver (eg: debug environments) can allow an attacker to crash the service (DoS). We recommend updating, or to restrict access in your debug environments.

Scores

CVSS v3 5.0
EPSS 0.0005
EPSS Percentile 16.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-401
Status published

Affected Products (1)

openthread/wpantund < 2020-05-28

Timeline

Published Jul 07, 2020
Tracked Since Feb 18, 2026