Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhjj-6gr2-w5wg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions.

The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions.

EPSS

Процентиль: 58%
0.00373
Низкий

Связанные уязвимости

CVSS3: 4.8
nvd
больше 5 лет назад

The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions.

EPSS

Процентиль: 58%
0.00373
Низкий