Description
The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-2524 | The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions. |
References
History
No history.
Status: PUBLISHED
Assigner: zephyr
Published:
Updated: 2024-09-17T02:07:14.701Z
Reserved: 2020-03-04T00:00:00.000Z
Link: CVE-2020-10059
No data.
Status : Modified
Published: 2020-05-11T23:15:11.973
Modified: 2024-11-21T04:54:43.450
Link: CVE-2020-10059
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD