Description
Predictable DTLS HelloVerifyRequest Cookie in NetX Secure
Published: 2026-09-29
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via predictable DTLS HelloVerifyRequest cookie
Action: Update Software
AI Analysis

Impact

The NetX Secure implementation produces a DTLS HelloVerifyRequest cookie that can be predicted by an attacker. This allows the attacker to bypass the initial client authentication step of the DTLS handshake, potentially enabling the attacker to forge connections, exhaust server resources, or hijack a session. The weakness is labeled CWE-330, indicating a flaw in securely handling authentication tokens or cookies.

Affected Systems

The affected product is NetX Duo, developed by the Eclipse Foundation. Specific version information is not provided in the available data, so all releases of NetX Duo that have not yet applied a fix are potentially vulnerable.

Risk and Exploitability

With a CVSS score of 6.3 the vulnerability is of medium severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified from current data. The vulnerability is not listed in the CISA KEV catalog, implying no known public exploitation at this time. However, the likely attack vector is over a network where a client initiates a DTLS session; an attacker could send crafted HelloVerifyRequest messages to cause resource exhaustion or to manipulate session establishment.

Generated by OpenCVE AI on September 29, 2026 at 21:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify if a newer NetX Duo release includes a patch for the DTLS cookie issue and upgrade the firmware accordingly.
  • If an immediate patch is not available, disable or restrict DTLS usage on networks handling sensitive traffic, or enforce stricter cookie generation parameters if configuration options exist.
  • Monitor TLS/DTLS connection attempts for repeated HelloVerifyRequest traffic and apply rate limiting or firewall rules to mitigate potential denial of service attacks.

Generated by OpenCVE AI on September 29, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Predictable DTLS HelloVerifyRequest Cookie in NetX Secure

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Predictable DTLS HelloVerifyRequest Cookie in NetX Secure
Weaknesses CWE-330
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:39:25.824Z

Reserved: 2026-09-29T16:15:15.514Z

Link: CVE-2026-102719

cve-icon Vulnrichment

Updated: 2026-09-29T18:39:16.650Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:11.240

Modified: 2026-09-29T19:17:21.067

Link: CVE-2026-102719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:00:08Z

Weaknesses
  • CWE-330

    Use of Insufficiently Random Values