CVE-2017-14032
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- arm/mbed tls · trustedfirmware/mbed tls
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2017/dsa-3967
- https://bugs.debian.org/873557Issue Tracking, Patch, Third Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/31458a18788b0cf0b722acda9bb2f2fe13a3fb32Issue Tracking, Patch, Third Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/d15795acd5074e0b44e71f7ede8bdfe1b48591fcIssue Tracking, Patch, Third Party Advisory
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2017-02Vendor Advisory
- http://www.debian.org/security/2017/dsa-3967
- https://bugs.debian.org/873557Issue Tracking, Patch, Third Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/31458a18788b0cf0b722acda9bb2f2fe13a3fb32Issue Tracking, Patch, Third Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/d15795acd5074e0b44e71f7ede8bdfe1b48591fcIssue Tracking, Patch, Third Party Advisory
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2017-02Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.