cbcvebase.
CVE-2020-13777
published 2020-06-04

CVE-2020-13777: GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in…

PriorityP357high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
17.51%
96.8th percentile
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiangnutls28< gnutls28 3.6.14-1 (bookworm)gnutls28 3.6.14-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
gnugnutls>= 3.6.0 < 3.6.143.6.14
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_gnutls_3.6.14-6_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.