CVE-2022-2576: High severity eclipse californium vulnerability
In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRequest. Especially, if used with certificate based cipher suites, that results in message amplification (DDoS other peers) and high CPU load (DoS own peer). The misbehavior occurs only with DTLSVERIFYPEERSONRESUMPTIONTHRESHOLD values larger than 0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2576?
CVE-2022-2576 is a vulnerability in Eclipse Californium that allows for a DTLS resumption handshake to fall back to a full handshake on a parameter mismatch, leading to potential DDoS attacks.
What is the severity of CVE-2022-2576?
CVE-2022-2576 has a severity rating of 7.5 (High).
Which versions of Eclipse Californium are affected by CVE-2022-2576?
CVE-2022-2576 affects Eclipse Californium versions 2.0.0 to 2.7.2 and 3.0.0 to 3.5.0.
How does CVE-2022-2576 impact the affected software?
CVE-2022-2576 can result in message amplification (DDoS other peers) if used with certificate-based cipher suites.
Is there a fix available for CVE-2022-2576?
At the moment, there is no known fix or patch available for CVE-2022-2576.