Skip to content

Missing Key ID Mode validation when processing 6LoWPAN frames

High
jwhui published GHSA-vr3r-363g-72j9 Jul 1, 2023

Package

OpenThread (OpenThread)

Affected versions

< 3d5cb36

Patched versions

3d5cb36

Description

Impact

  • The Thread Specification requires processing received IEEE 802.15.4 frames with Security Enabled using Key ID Mode 2 as unsecure.
  • OpenThread did not conform to the Thread Specification and processed all IEEE 802.15.4 frames with Security Enabled as secure, including those using Key ID Mode 2.
  • This vulnerability makes it possible to inject arbitrary IPv6 datagrams without possession of the Thread Network Key.

Patches

Severity

High
7.5
/ 10

CVSS base metrics

Attack vector
Adjacent
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE ID

CVE-2023-2626

Weaknesses