CVE Vulnerabilities

CVE-2021-34433

Improper Verification of Cryptographic Signature

Published: Aug 20, 2021 | Modified: Aug 26, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server sides signature on the client side, if that signature is not included in the servers ServerKeyExchange.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Californium Eclipse 2.0.0 (including) 2.6.5 (excluding)
Californium Eclipse 3.0.0-m1 (including) 3.0.0-m1 (including)
Californium Eclipse 3.0.0-m2 (including) 3.0.0-m2 (including)
Californium Eclipse 3.0.0-m3 (including) 3.0.0-m3 (including)

References