VulnerabilityModified
CVE-2021-28681
The PeerConnectionState was set to failed, but a user could ignore that and continue to use the PeerConnection. )A WebRTC implementation shouldn't allow the user to continue if verification has failed.)
MEDIUM 5.3EPSS 0.68%
Does this matter?
Lower severity and a low EPSS score (0.68%). Track it; it rarely justifies an emergency change on its own.
Description
Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerConnectionState was set to failed, but a user could ignore that and continue to use the PeerConnection. )A WebRTC implementation shouldn't allow the user to continue if verification has failed.)
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- webrtc project/webrtc
- Source
- cve@mitre.org
References
- https://github.com/pion/webrtc/issues/1708Exploit, Patch, Third Party Advisory
- https://github.com/pion/webrtc/security/advisories/GHSA-74xm-qj29-cq8pThird Party Advisory
- https://github.com/pion/webrtc/issues/1708Exploit, Patch, Third Party Advisory
- https://github.com/pion/webrtc/security/advisories/GHSA-74xm-qj29-cq8pThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.