CVE-2021-34430

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
08/07/2021
Last modified:
12/07/2021

Description

Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:tinydtls:*:*:*:*:*:*:*:* 0.8.2 (including)
cpe:2.3:a:eclipse:tinydtls:0.9:rc1:*:*:*:*:*:*


References to Advisories, Solutions, and Tools