Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Riot/
  3. Riot

Riot

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 18 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Employee security posture mgmt platform with awareness training & scoring.

by Riot · tryriot.com · source ↗

Known CVEs (18)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2021-41061 ↗MEDIUM 5.52021

    In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots.

  • CVE-2021-31664 ↗HIGH 7.52021

    RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information.

  • CVE-2021-31663 ↗HIGH 7.52021

    RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d74985371e4f22d79 contains a buffer overflow which could allow attackers to obtain sensitive information.

  • CVE-2021-31662 ↗HIGH 7.52021

    RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to obtain sensitive information.

  • CVE-2021-31661 ↗HIGH 7.52021

    RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba157c112658 contains a buffer overflow that could allow attackers to obtain sensitive information.

  • CVE-2021-31660 ↗HIGH 7.52021

    RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information.

  • CVE-2021-27698 ↗CRITICAL 9.82021

    RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c through the _parse_options() function.

  • CVE-2021-27697 ↗CRITICAL 9.82021

    RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the gnrc_rpl_validation_options() function.

  • CVE-2021-27357 ↗CRITICAL 9.82021

    RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c.

  • CVE-2020-15350 ↗CRITICAL 9.82020

    RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation function to compute the required buffer capacity and validate against t…

  • CVE-2020-1627 ↗HIGH 7.52020

    A vulnerability in Juniper Networks Junos OS on vMX and MX150 devices may allow an attacker to cause a Denial of Service (DoS) by sending specific packets requiring special processing in microcode tha…

  • CVE-2019-17389 ↗HIGH 7.52019

    In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to preve…

  • CVE-2019-16754 ↗HIGH 7.52019

    RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a network node running RIOT. This requires spoofing an MQTT server …

  • CVE-2019-15702 ↗HIGH 7.52019

    In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_t…

  • CVE-2019-15134 ↗HIGH 7.52019

    RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all memory available for network packets and thus effectively stopping all network thr…

  • CVE-2019-1000006 ↗CRITICAL 9.82019

    RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in sock_dns, an implementation of the DNS protocol utilizing the RIOT sock API that …

  • CVE-2016-10527 ↗HIGH 7.52018

    The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions.

  • CVE-2017-8289 ↗CRITICAL 9.82017

    Stack-based buffer overflow in the ipv6_addr_from_str function in sys/net/network_layer/ipv6/addr/ipv6_addr_from_str.c in RIOT prior to 2017-04-25 allows local attackers, and potentially remote attack…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other GRC & Compliance Automation products

see all →
  • 3rdRisk Platform · 3rdRisk Solutions B.V.
  • 3rdcomply · 3rdcomply
  • 6clicks GRC · 6clicks
  • A-LIGN A-SCEND · A-LIGN
  • ANOZR WAY AY PeopleSight · ANOZR WAY
  • ARCON Security Compliance Management · ARCON
  • ASPIA Audit Management · ASPIA Infotech Pvt. Ltd.
  • ASPIA KRI Module · ASPIA Infotech Pvt. Ltd.