CVE-2019-20786

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
19/04/2020
Last modified:
23/04/2020

Description

handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after handshake completion.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pion:dtls:*:*:*:*:*:*:*:* 1.5.2 (excluding)