Skip to main content

Vendor/product archive

eclipse / californium CVEs

Beta · best-effort

4 CVEs tagged to eclipse / californium0 Critical, 4 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2022-39368

Published Nov 10, 2022

Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud services. In versions prior to 3.7.0, and 2.7.4, Californium is vulnerable…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2576

Published Jul 29, 2022

In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34433

Published Aug 20, 2021

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server sid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27222

Published Feb 3, 2021

In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal sta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1