CVE-2017-7243: Null Pointer Dereference
Published Mar 24, 2017
·Updated
Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.
Affected Software
1 affected component
Eclipse tinydtls=0.8.2
Event History
Mar 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7243?
CVE-2017-7243 has a severity rating of medium, as it can lead to a denial of service via DTLS peer crash.
2
How do I fix CVE-2017-7243?
To fix CVE-2017-7243, you should upgrade to a patched version of Eclipse TinyDTLS beyond 0.8.2, if available.
3
What kind of attack does CVE-2017-7243 enable?
CVE-2017-7243 enables remote attackers to cause a denial of service by sending invalid packets.
4
Which version of Eclipse TinyDTLS is affected by CVE-2017-7243?
Eclipse TinyDTLS version 0.8.2 is the version affected by CVE-2017-7243.
5
What happens if CVE-2017-7243 is exploited?
If CVE-2017-7243 is exploited, the affected DTLS peer can crash, leading to service disruption.