Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27222

Опубликовано: 03 фев. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The DTLS server side must be restarted to recover this. This allow clients to force a DoS.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:eclipse:californium:*:*:*:*:*:*:*:*
Версия от 2.3.0 (включая) до 2.6.0 (включая)

EPSS

Процентиль: 45%
0.00226
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-372
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.5
redhat
около 5 лет назад

In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The DTLS server side must be restarted to recover this. This allow clients to force a DoS.

github
больше 3 лет назад

In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because it sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshakes failure with TLS parameter mismatch. The server must be restarted to recover this. This allow clients to force a DoS.

EPSS

Процентиль: 45%
0.00226
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-372
NVD-CWE-Other