PT-2024-11024 · Unknown · Contiki-Ng

Jerrytesting

·

Published

2024-01-24

·

Updated

2024-02-01

·

CVE-2021-42146

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Contiki-NG tinyDTLS through master branch 53a0d97
Description An issue was discovered in DTLS servers, allowing remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This allows remote attackers to obtain sensitive application data of connected clients.
Recommendations For Contiki-NG tinyDTLS through master branch 53a0d97, consider disabling the DTLS server functionality until a patch is available to prevent remote attackers from reusing the same epoch number and obtaining sensitive application data. Restrict access to the DTLS server to minimize the risk of exploitation. Avoid using the DTLS protocol with the current implementation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2021-42146

Affected Products

Contiki-Ng