Input validation error in Eclipse Californium - CVE-2020-27222
Published: February 3, 2021 / Updated: February 8, 2021
Eclipse Californium
Eclipse
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a DTLS handshake failure with TLS parameter mismatch when setting the internal state. A remote attacker can cause the certificate based (x509 and RPK) DTLS handshakes to fail and perform a denial of service (DoS) attack.