Contiki-NG tinyDTLS Epoch Number Reuse
2024-1-18 23:41:4 Author: packetstormsecurity.com(查看原文) 阅读量:8 收藏

[Suggested description]
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote attackers to obtain sensitive application (data of connected clients).

[VulnerabilityType Other]
Improper Handling of exception conditions

[Vendor of Product]
https://github.com/contiki-ng/tinydtls

[Affected Product Code Base]
contiki-ng tinydtls - master branch 53a0d97

[Affected Component]
the service of dtls servers

[Attack Type]
Remote

[Impact Code execution]
true

[Impact Information Disclosure]
true

[Reference]
https://github.com/contiki-ng/tinydtls/issues/25

[Discoverer]
jerrytesting

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2021-42146 to this vulnerability.


文章来源: https://packetstormsecurity.com/files/176630/cngtinydtls-epochreuse.txt
如有侵权请联系:admin#unsafe.sh