← Back

CVE-2021-34433

nvd nist
Published: Aug 20, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.

Affected (4)

Products: Eclipse: Californium
1 product
Californium
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
From 2.0.0 to 2.6.5
Version 3.0.0 m1
Version 3.0.0 m2
Version 3.0.0 m3

References (2)

Source: emo@eclipse.org
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.