Denial of Service Vulnerability in Contiki-NG tinyDTLS
CVE-2021-42141
9.8CRITICAL
What is CVE-2021-42141?
A vulnerability exists in the tinyDTLS implementation within the Contiki-NG framework, which stems from improper handling of handshake sequences. This flaw occurs when a handshake completes with mismatched epoch numbers across multiple packets, specifically during the Client_Hello, Client_key_exchange, and Change_cipher_spec exchanges. As a result, this inconsistency can lead to a denial of service, making the affected system unresponsive or inaccessible.