7.5
CVSSv3

CVE-2021-42146

Published: 24/01/2024 Updated: 01/02/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote malicious users to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote malicious users to obtain sensitive application (data of connected clients).

Vulnerable Product Search on Vulmon Subscribe to Product

contiki-ng tinydtls 2018-08-30

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Misues same epoch number within TCP lifetime in TinyDTLS <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: ...