An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote attackers to obtain sensitive application (data of connected clients).
References
Link Resource
https://seclists.org/fulldisclosure/2024/Jan/19 Mailing List Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2024-01-24T00:00:00

Updated: 2024-01-24T19:03:00.282220

Reserved: 2021-10-11T00:00:00


Link: CVE-2021-42146

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-24T19:15:08.483

Modified: 2024-02-01T20:16:49.277


Link: CVE-2021-42146

JSON object: View

cve-icon Redhat Information

No data.

CWE