CVE-2020-27222
In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The DTLS server side must be restarted to recover this. This allow clients to force a DoS.
Scoring
- CVSS base score
- 0.01
- EPSS probability
- 0.23%
- CWE
- CWE-372
- Published
- 2021-02-03
- Last modified
- 2026-03-14
Affected products
- The Eclipse Foundation Eclipse Californium
Weakness type
Related vulnerabilities
- CVE-2026-41388 — OpenClaw < 2026.3.31 - Configuration Rehydration via Empty-Array Revocation Handling
- CVE-2026-41340 — OpenClaw < 2026.3.31 - Authentication Boundary Bypass via Telegram Legacy allowFrom Migration
- CVE-2026-41300 — OpenClaw < 2026.3.31 - Preservation of Attacker-Discovered Endpoints in Remote Onboarding
- CVE-2023-4012 — Incomplete Internal State Distinction in ntpsec
- CVE-2023-36834 — Junos OS: SRX 4600 and SRX 5000 Series: The receipt of specific genuine packets by SRXes configured for L2 transparency will cause a DoS
- CVE-2023-31127 — DMTF-2023-0001: SPDM mutual authentication bypass
- CVE-2021-25735 — Validating Admission Webhook does not observe some previous fields