CVE Vulnerabilities

CVE-2021-34433

Key Exchange without Entity Authentication

Published: Aug 20, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server sides signature on the client side, if that signature is not included in the servers ServerKeyExchange.

Weakness

The product performs a key exchange with an actor without verifying the identity of that actor.

Affected Software

Name Vendor Start Version End Version
Californium Eclipse 2.0.0 (including) 2.6.5 (excluding)
Californium Eclipse 3.0.0-m1 (including) 3.0.0-m1 (including)
Californium Eclipse 3.0.0-m2 (including) 3.0.0-m2 (including)
Californium Eclipse 3.0.0-m3 (including) 3.0.0-m3 (including)

Potential Mitigations

References