8.1

CVE-2017-2784

Exploit
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library, can cause an invalid free of a stack pointer leading to a potential remote code execution. In order to exploit this vulnerability, an attacker can act as either a client or a server on a network to deliver malicious x509 certificates to vulnerable applications.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TrustedfirmwareMbed Tls Version <= 1.3.18
TrustedfirmwareMbed Tls Version2.0.0
TrustedfirmwareMbed Tls Version2.1.0
TrustedfirmwareMbed Tls Version2.1.1
TrustedfirmwareMbed Tls Version2.1.2
TrustedfirmwareMbed Tls Version2.1.3
TrustedfirmwareMbed Tls Version2.1.4
TrustedfirmwareMbed Tls Version2.1.5
TrustedfirmwareMbed Tls Version2.1.6
TrustedfirmwareMbed Tls Version2.4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.42% 0.877
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Cisco Talos 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://security.gentoo.org/glsa/201706-18
http://www.talosintelligence.com/reports/TALOS-2017-0274/
Third Party Advisory
Exploit
VDB Entry
Technical Description
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2017-01
Vendor Advisory
Mitigation