CVE-2020-27222: High severity eclipse californium vulnerability
A flaw was found in californium. The certificate based (x509 and RPK) DTLS handshakes fails due to the DTLS server side being set to a wrong internal state by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The highest threat from this vulnerability is to system availability.
Other sources
In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The DTLS server side must be restarted to recover this. This allow clients to force a DoS.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-27222?
CVE-2020-27222 is a vulnerability found in Eclipse Californium versions 2.3.0 to 2.6.0.
How does CVE-2020-27222 impact the affected software?
CVE-2020-27222 can cause certificate-based DTLS handshakes to fail in Eclipse Californium, leading to potential security issues.
What is the severity of CVE-2020-27222?
CVE-2020-27222 has a severity rating of high with a CVSS score of 7.5.
How can I fix CVE-2020-27222?
To fix CVE-2020-27222, upgrade to Eclipse Californium version 2.6.1 or later.
Where can I find more information about CVE-2020-27222?
You can find more information about CVE-2020-27222 on the CVE website (https://www.cve.org/CVERecord?id=CVE-2020-27222) and the NVD website (https://nvd.nist.gov/vuln/detail/CVE-2020-27222).