In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NEclipse Californium
APPEclipse3.0.02.0.0 – 2.6.5 (excl.)
Related vulnerabilities
Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud servi...
In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS...
In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidental...
Eclipse GlassFish: CSRF+SSRF w DownloadServlet umożliwia przejęcie domeny
Eclipse Milo: padding oracle w uwierzytelnianiu OPC-UA umożliwia odzyskanie hasła