{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "2.0.0"
              },
              {
                "fixed": "2.6.5"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.0-m1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.0-m2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.0-m3"
              }
            ]
          },
          "events": [
            {
              "introduced": "15a27a972d7b4dd8d28d717cedfd01e6bf860e38"
            },
            {
              "fixed": "896b12c5a582787bed4dc971b0b0f675009b2401"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "8f6f689bcc03377f682d8c3b86c705ce02225afd"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "3d658da87c30784272d4d205e0ad950845bcdb64"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "b5780bb2e17efb708e46242a204094ff1cdad034"
            }
          ],
          "repo": "https://github.com/eclipse/californium",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.",
  "id": "CVE-2021-34433",
  "modified": "2026-03-13T21:50:35.220227129Z",
  "published": "2021-08-20T17:15:07.687Z",
  "references": [
    {
      "type": "REPORT",
      "url": "https://bugs.eclipse.org/bugs/show_bug.cgi?id=575281"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}