Impact
The NetX Secure implementation produces a DTLS HelloVerifyRequest cookie that can be predicted by an attacker. This allows the attacker to bypass the initial client authentication step of the DTLS handshake, potentially enabling the attacker to forge connections, exhaust server resources, or hijack a session. The weakness is labeled CWE-330, indicating a flaw in securely handling authentication tokens or cookies.
Affected Systems
The affected product is NetX Duo, developed by the Eclipse Foundation. Specific version information is not provided in the available data, so all releases of NetX Duo that have not yet applied a fix are potentially vulnerable.
Risk and Exploitability
With a CVSS score of 6.3 the vulnerability is of medium severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified from current data. The vulnerability is not listed in the CISA KEV catalog, implying no known public exploitation at this time. However, the likely attack vector is over a network where a client initiates a DTLS session; an attacker could send crafted HelloVerifyRequest messages to cause resource exhaustion or to manipulate session establishment.
OpenCVE Enrichment