CVE-2020-27222

CVE-2020-27222

In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because it sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshakes failure with TLS parameter mismatch. The server must be restarted to recover this. This allow clients to force a DoS.

Source: CVE-2020-27222

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다