7.5
CVE-2021-34433
- EPSS 0.05%
- Published 20.08.2021 17:15:07
- Last modified 21.11.2024 06:10:24
- Source emo@eclipse.org
- Teams watchlist Login
- Open Login
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.
Data is provided by the National Vulnerability Database (NVD)
Eclipse ≫ Californium Version >= 2.0.0 < 2.6.5
Eclipse ≫ Californium Version3.0.0 Updatem1
Eclipse ≫ Californium Version3.0.0 Updatem2
Eclipse ≫ Californium Version3.0.0 Updatem3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.116 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-322 Key Exchange without Entity Authentication
The product performs a key exchange with an actor without verifying the identity of that actor.
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.