Vulnerability Details CVE-2021-34430
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-34430
-
cpe:2.3:a:eclipse:tinydtls:0.8.1
-
cpe:2.3:a:eclipse:tinydtls:0.8.2
-
cpe:2.3:a:eclipse:tinydtls:0.9