CVE-2020-11501
published 2020-04-03CVE-2020-11501: GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06…
PriorityP344high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
3.39%
87.5th percentile
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | gnutls28 | < gnutls28 3.6.13-2 (bookworm) | gnutls28 3.6.13-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | gnutls | >= 3.6.3 < 3.6.13 | 3.6.13 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_gnutls_3.6.14-6_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j883-wjrw-g444: GnuTLS 3
ghsa_unreviewed·2022-05-24
CVE-2020-11501 [MEDIUM] CWE-327 GHSA-j883-wjrw-g444: GnuTLS 3
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
OSV
CVE-2020-11501: GnuTLS 3
osv·2020-04-03·CVSS 7.4
CVE-2020-11501 [HIGH] CVE-2020-11501: GnuTLS 3
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Microsoft
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' byt
vendor_msrc·2020-04-14·CVSS 7.4
CVE-2020-11501 [HIGH] CWE-330 GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' byt
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2020-04-07
CVE-2020-11501 GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could expose sensitive information over the network.
It was discovered that GnuTLS incorrectly handled randomness when
performing DTLS negotiation. A remote attacker could possibly use this
issue to obtain sensitive information, contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: DTLS client hello contains a random value of all zeroes
vendor_redhat·2020-03-27·CVSS 7.4
CVE-2020-11501 [HIGH] CWE-327 gnutls: DTLS client hello contains a random value of all zeroes
gnutls: DTLS client hello contains a random value of all zeroes
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
A cryptographic weakness was found in the way DLTS implementation of GnuTLS, used zeros in place of random numbers. This flaw can break the security guarantee of the DTLS protocol.
Statement: The earliest affected version is gnuTLS-3.6.3. Therefore versions of gnuTLS shipped with Red Hat Enterprise Linux 5, 6 and 7 are not affected by this flaw.
Package: gnutls (Red Hat Enterprise Li
Debian
CVE-2020-11501: gnutls28 - GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest af...
vendor_debian·2020·CVSS 7.4
CVE-2020-11501 [HIGH] CVE-2020-11501: gnutls28 - GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest af...
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
Scope: local
bookworm: resolved (fixed in 3.6.13-2)
bullseye: resolved (fixed in 3.6.13-2)
forky: resolved (fixed in 3.6.13-2)
sid: resolved (fixed in 3.6.13-2)
trixie: resolved (fixed in 3.6.13-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11501 gnutls: DTLS client hello contains a random value of all zeroes
bugzilla·2020-04-07·CVSS 7.4
CVE-2020-11501 [HIGH] CVE-2020-11501 gnutls: DTLS client hello contains a random value of all zeroes
CVE-2020-11501 gnutls: DTLS client hello contains a random value of all zeroes
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
References:
https://gitlab.com/gnutls/gnutls/-/issues/960
https://www.gnutls.org/security-new.html#GNUTLS-SA-2020-03-31
Discussion:
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1821898]
Created mingw-gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1821899]
---
Statement:
The earliest affected version is gnuTLS-3.6.3. Theref
Bugzilla
CVE-2020-11501 gnutls: DTLS client hello contains a random value of all zeroes [fedora-all]
bugzilla·2020-04-07·CVSS 7.4
CVE-2020-11501 [HIGH] CVE-2020-11501 gnutls: DTLS client hello contains a random value of all zeroes [fedora-all]
CVE-2020-11501 gnutls: DTLS client hello contains a random value of all zeroes [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-11501 mingw-gnutls: gnutls: DTLS client hello contains a random value of all zeroes [fedora-all]
bugzilla·2020-04-07·CVSS 7.4
CVE-2020-11501 [HIGH] CVE-2020-11501 mingw-gnutls: gnutls: DTLS client hello contains a random value of all zeroes [fedora-all]
CVE-2020-11501 mingw-gnutls: gnutls: DTLS client hello contains a random value of all zeroes [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00015.htmlhttps://gitlab.com/gnutls/gnutls/-/commit/5b595e8e52653f6c5726a4cdd8fddeb6e83804d2https://gitlab.com/gnutls/gnutls/-/issues/960https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/https://security.gentoo.org/glsa/202004-06https://security.netapp.com/advisory/ntap-20200416-0002/https://usn.ubuntu.com/4322-1/https://www.debian.org/security/2020/dsa-4652https://www.gnutls.org/security-new.html#GNUTLS-SA-2020-03-31http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00015.htmlhttps://gitlab.com/gnutls/gnutls/-/commit/5b595e8e52653f6c5726a4cdd8fddeb6e83804d2https://gitlab.com/gnutls/gnutls/-/issues/960https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/https://security.gentoo.org/glsa/202004-06https://security.netapp.com/advisory/ntap-20200416-0002/https://usn.ubuntu.com/4322-1/https://www.debian.org/security/2020/dsa-4652https://www.gnutls.org/security-new.html#GNUTLS-SA-2020-03-31
2020-04-03
Published