ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
The code uses a variable that has not been initialized, leading to unpredictable or unintended results.
The product uses or accesses a resource that has not been initialized.
Link | Tags |
---|---|
https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/ | third party advisory exploit |