Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-42146

Опубликовано: 24 янв. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote attackers to obtain sensitive application (data of connected clients).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:contiki-ng:tinydtls:2018-08-30:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00087
Низкий

7.5 High

CVSS3

Дефекты

CWE-755
CWE-303

Связанные уязвимости

CVSS3: 7.5
github
около 2 лет назад

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote attackers to obtain sensitive application (data of connected clients).

EPSS

Процентиль: 25%
0.00087
Низкий

7.5 High

CVSS3

Дефекты

CWE-755
CWE-303