First published: Fri Mar 24 2017(Updated: )
Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse TinyDTLS | =0.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7243 has a severity rating of medium, as it can lead to a denial of service via DTLS peer crash.
To fix CVE-2017-7243, you should upgrade to a patched version of Eclipse TinyDTLS beyond 0.8.2, if available.
CVE-2017-7243 enables remote attackers to cause a denial of service by sending invalid packets.
Eclipse TinyDTLS version 0.8.2 is the version affected by CVE-2017-7243.
If CVE-2017-7243 is exploited, the affected DTLS peer can crash, leading to service disruption.