VYPR

UpdateHub

by Zephyrproject Rtos

Source repositories

CVEs (1)

  • CVE-2020-10059MedMay 11, 2020
    risk 0.00cvss 4.8epss 0.01

    The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects:…