SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-36478

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS).

HIGH 7.5EPSS 1.18%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
1.18% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
arm/mbed tls · siemens/logo\! cmr2020 firmware · siemens/logo\! cmr2040 firmware · siemens/simatic rtu3031c firmware · siemens/simatic rtu3041c firmware · siemens/simatic rtu3030c firmware · siemens/simatic rtu3000c firmware · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.