Vulnerabilities > Eclipse > Tinydtls > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-07-08 | CVE-2021-34430 | Inadequate Encryption Strength vulnerability in Eclipse Tinydtls 0.8.1/0.8.2/0.9 Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic. | 7.5 |
2017-03-24 | CVE-2017-7243 | NULL Pointer Dereference vulnerability in Eclipse Tinydtls 0.8.2 Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake. | 7.5 |