CVE-2021-34430: Weak Encryption
Published Jul 8, 2021
·Updated
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.
Affected Software
2 affected components
Eclipse tinydtls<=0.8.2
Eclipse tinydtls=0.9-rc1
Event History
Jul 8, 2021
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-34430?
CVE-2021-34430 is classified as a high severity vulnerability that could allow attackers to decrypt DTLS traffic.
2
How do I fix CVE-2021-34430?
To fix CVE-2021-34430, upgrade Eclipse TinyDTLS to version 0.9-rc2 or later.
3
What are the implications of CVE-2021-34430?
The implications of CVE-2021-34430 include potential exposure of sensitive data due to insecure random number generation.
4
Which versions of Eclipse TinyDTLS are affected by CVE-2021-34430?
Eclipse TinyDTLS versions up to and including 0.8.2 and 0.9-rc1 are affected by CVE-2021-34430.
5
Can CVE-2021-34430 be exploited remotely?
Yes, CVE-2021-34430 can be exploited remotely, allowing attackers to compute the master key from compromised DTLS traffic.