CVE-2021-42144

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
24/01/2024
Last modified:
20/06/2025

Description

Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information via crafted input to dtls_ccm_decrypt_message().

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:contiki-ng:contiki-ng_tinydtls:*:*:*:*:*:*:*:* 2018-08-30 (including)