CVE-2021-42144
Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information via crafted input to dtls_ccm_decrypt_message().
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42144?
CVE-2021-42144 is classified as a medium severity vulnerability due to the potential for sensitive information exposure.
How do I fix CVE-2021-42144?
To fix CVE-2021-42144, update to a version of Contiki-NG tinyDTLS that has addressed this buffer over-read vulnerability.
What types of systems are affected by CVE-2021-42144?
CVE-2021-42144 affects systems running Contiki-NG tinyDTLS versions up to and including 2018-08-30.
Can CVE-2021-42144 be exploited remotely?
Yes, CVE-2021-42144 can be exploited remotely by attackers who send crafted input to trigger the buffer over-read.
What are the potential impacts of CVE-2021-42144?
The potential impacts of CVE-2021-42144 include unauthorized access to sensitive information processed by vulnerable instances of tinyDTLS.