Lucene search

K
osvGoogleOSV:CVE-2021-34433
HistoryAug 20, 2021 - 5:15 p.m.

CVE-2021-34433

2021-08-2017:15:07
Google
osv.dev
6

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.0%

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side’s signature on the client side, if that signature is not included in the server’s ServerKeyExchange.

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.0%

Related for OSV:CVE-2021-34433