Vulnerability Description
In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The DTLS server side must be restarted to recover this. This allow clients to force a DoS.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Californium | >= 2.3.0, <= 2.6.0 |
Related Weaknesses (CWE)
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=570844Permissions RequiredVendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=570844Permissions RequiredVendor Advisory
FAQ
What is CVE-2020-27222?
CVE-2020-27222 is a vulnerability with a CVSS score of 7.5 (HIGH). In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong intern...
How severe is CVE-2020-27222?
CVE-2020-27222 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27222?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Californium.