7.5

CVE-2020-36478

Exploit

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.

Data is provided by the National Vulnerability Database (NVD)
ArmMbed Tls Version < 2.7.18
ArmMbed Tls Version >= 2.8.0 < 2.16.9
ArmMbed Tls Version >= 2.17.0 < 2.25.0
SiemensLogo! Cmr2020 Firmware Version < 2.2
   SiemensLogo! Cmr2020 Version-
SiemensLogo! Cmr2040 Firmware Version < 2.2
   SiemensLogo! Cmr2040 Version-
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.451
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.