Denial of Service Vulnerability in Contiki-NG's tinyDTLS Implementation
CVE-2021-42143

9.1CRITICAL

Key Information:

Vendor

Contiki-ng

Status
Vendor
CVE Published:
24 January 2024

What is CVE-2021-42143?

An issue within the tinyDTLS implementation of Contiki-NG has been identified where an infinite loop is triggered during the processing of a ClientHello handshake message. This vulnerability allows remote attackers to exploit the system by sending specially crafted handshake messages that contain an odd length of cipher suites. The resultant infinite loop can lead to resource exhaustion, precipitating a denial of service. Additionally, the handling of such messages can also cause buffer over-reads, potentially exposing sensitive information to unauthorized entities.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.