CVE-2021-42142: Critical severity contiki-ng vulnerability
Published Jan 23, 2024
·Updated
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vulnerability allows remote attackers to cause a denial of service and false-positive packet drops.
Affected Software
1 affected component
Contiki-NG tinyDTLS<=2018-08-30
Remediation
Patch Available
Event History
Jan 23, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-42142?
CVE-2021-42142 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2021-42142?
To fix CVE-2021-42142, update to a version of tinyDTLS released after August 30, 2018.
3
What impact does CVE-2021-42142 have on DTLS servers?
CVE-2021-42142 can cause denial of service and false-positive packet drops on DTLS servers.
4
Are all versions of tinyDTLS affected by CVE-2021-42142?
Only versions of tinyDTLS up to and including 2018-08-30 are affected by CVE-2021-42142.
5
Who can exploit CVE-2021-42142?
CVE-2021-42142 can be exploited by remote attackers to disrupt DTLS server operations.