Lucene search

K
cveMitreCVE-2021-42146
HistoryJan 24, 2024 - 7:15 p.m.

CVE-2021-42146

2024-01-2419:15:08
CWE-755
mitre
web.nvd.nist.gov
13
contiki-ng
tinydtls
cve-2021-42146
security vulnerability
remote attackers
sensitive data
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

42.3%

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote attackers to obtain sensitive application (data of connected clients).

Affected configurations

Nvd
Node
contiki-ngtinydtlsMatch2018-08-30
VendorProductVersionCPE
contiki-ngtinydtls2018-08-30cpe:2.3:a:contiki-ng:tinydtls:2018-08-30:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

42.3%

Related for CVE-2021-42146