7.5
CVE-2020-8286
- EPSS 4.58%
- Veröffentlicht 14.12.2020 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:38:39
- Erkennungen
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Netapp ≫ Clustered Data Ontap Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Hci Bootstrap Os Version -
Netapp ≫ Hci Storage Node Firmware Version -
Siemens ≫ Simatic Tim 1531 Irc Firmware Version <= 2.2
Siemens ≫ Sinec Infrastructure Network Services Version < 1.0.1.1
Oracle ≫ Communications Billing And Revenue Management Version 12.0.0.3.0
Oracle ≫ Communications Cloud Native Core Policy Version 1.14.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.58
Splunk ≫ Universal Forwarder Version >= 8.2.0 < 8.2.12
Splunk ≫ Universal Forwarder Version >= 9.0.0 < 9.0.6
Splunk ≫ Universal Forwarder Version 9.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.58% | 0.904 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
http://seclists.org/fulldisclosure/2021/Apr/51
https://support.apple.com/kb/HT212326
https://support.apple.com/kb/HT212327
https://support.apple.com/kb/HT212325
https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf
https://www.debian.org/security/2021/dsa-4881
https://security.gentoo.org/glsa/202012-14
https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/
https://security.netapp.com/advisory/ntap-20210122-0007/
http://seclists.org/fulldisclosure/2021/Apr/50
http://seclists.org/fulldisclosure/2021/Apr/54
https://curl.se/docs/CVE-2020-8286.html
https://hackerone.com/reports/1048457