CVE-2020-13777
published 2020-06-04CVE-2020-13777: GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in…
PriorityP357high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
17.51%
96.8th percentile
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | gnutls28 | < gnutls28 3.6.14-1 (bookworm) | gnutls28 3.6.14-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | gnutls | >= 3.6.0 < 3.6.14 | 3.6.14 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_gnutls_3.6.14-6_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Microsoft
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2 and an authentication bypass in TLS 1.3). The earliest affected version is
vendor_msrc·2020-06-09·CVSS 7.4
CVE-2020-13777 [HIGH] CWE-327 GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2 and an authentication bypass in TLS 1.3). The earliest affected version is
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2 and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation the TLS server always uses wrong data in place of an encryption key derived from an application.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to tran
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2020-06-05
CVE-2020-13777 GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to expose sensitive information.
It was discovered that GnuTLS incorrectly handled session ticket encryption
keys. A remote attacker could possibly use this issue to bypass
authentication or recover sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: session resumption works without master key allowing MITM
vendor_redhat·2020-06-03·CVSS 7.4
CVE-2020-13777 [HIGH] CWE-345 gnutls: session resumption works without master key allowing MITM
gnutls: session resumption works without master key allowing MITM
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.
A flaw was found in GnuTLS, in versions starting from 3.6.4, where it does not session the ticket encryption key in a secure fashion by the application which is connecting. This flaw allows an attacker to craft a man-in-the-middle-attack, with the ability to bypass the TLS1.3 authentication and also recover older conversations when TLS1.2
Debian
CVE-2020-13777: gnutls28 - GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ...
vendor_debian·2020·CVSS 7.4
CVE-2020-13777 [HIGH] CVE-2020-13777: gnutls28 - GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ...
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.
Scope: local
bookworm: resolved (fixed in 3.6.14-1)
bullseye: resolved (fixed in 3.6.14-1)
forky: resolved (fixed in 3.6.14-1)
sid: resolved (fixed in 3.6.14-1)
trixie: resolved (fixed in 3.6.14-1)
GHSA
GHSA-cv49-m792-xmjv: GnuTLS 3
ghsa_unreviewed·2022-05-24
CVE-2020-13777 [MEDIUM] CWE-327 GHSA-cv49-m792-xmjv: GnuTLS 3
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.
OSV
CVE-2020-13777: GnuTLS 3
osv·2020-06-04·CVSS 7.4
CVE-2020-13777 [HIGH] CVE-2020-13777: GnuTLS 3
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-13777 gnutls: session resumption works without master key allowing MITM
bugzilla·2020-06-03·CVSS 7.4
CVE-2020-13777 [HIGH] CVE-2020-13777 gnutls: session resumption works without master key allowing MITM
CVE-2020-13777 gnutls: session resumption works without master key allowing MITM
GnuTLS servers are able to use tickets issued by each other without access to the secret key as generated by gnutls_session_ticket_key_generate(). In TLS 1.3 this allows a MITM server without valid credentials to resume sessions with a client that first established an initial connection with a server with valid credentials. In TLS 1.2, it may allow attackers to recover the previous conversations.
Reference:
https://gitlab.com/gnutls/gnutls/-/issues/1011
Discussion:
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1843724]
Created gnutls30 tracking bugs for this issue:
Affects: epel-6 [bug 1843726]
Created mingw-gnutls tracking bugs for this issue:
Affects: fedora-all [bug 184372
Bugzilla
CVE-2020-13777 gnutls30: gnutls: session resumption works without master key allowing MITM [epel-6]
bugzilla·2020-06-03·CVSS 7.4
CVE-2020-13777 [HIGH] CVE-2020-13777 gnutls30: gnutls: session resumption works without master key allowing MITM [epel-6]
CVE-2020-13777 gnutls30: gnutls: session resumption works without master key allowing MITM [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following tem
Bugzilla
CVE-2020-13777 gnutls: session resumption works without master key allowing MITM [fedora-all]
bugzilla·2020-06-03·CVSS 7.4
CVE-2020-13777 [HIGH] CVE-2020-13777 gnutls: session resumption works without master key allowing MITM [fedora-all]
CVE-2020-13777 gnutls: session resumption works without master key allowing MITM [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2020-13777 mingw-gnutls: gnutls: session resumption works without master key allowing MITM [fedora-all]
bugzilla·2020-06-03·CVSS 7.4
CVE-2020-13777 [HIGH] CVE-2020-13777 mingw-gnutls: gnutls: session resumption works without master key allowing MITM [fedora-all]
CVE-2020-13777 mingw-gnutls: gnutls: session resumption works without master key allowing MITM [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00015.htmlhttps://gnutls.org/security-new.html#GNUTLS-SA-2020-06-03https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6C4DHUKV6M6SJ5CV6KVHZNHNF7HCUE5P/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RTXZOXC4MHTFE2HKY6IAZMF2WHD2WMV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RRQBFK3UZ7SV76IYDTS4PS6ABS2DSJHK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMB3UGI5H5RCFRU6OGRPMNUCNLJGEN7Y/https://security.gentoo.org/glsa/202006-01https://security.netapp.com/advisory/ntap-20200619-0004/https://usn.ubuntu.com/4384-1/https://www.debian.org/security/2020/dsa-4697http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00015.htmlhttps://gnutls.org/security-new.html#GNUTLS-SA-2020-06-03https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6C4DHUKV6M6SJ5CV6KVHZNHNF7HCUE5P/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RTXZOXC4MHTFE2HKY6IAZMF2WHD2WMV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RRQBFK3UZ7SV76IYDTS4PS6ABS2DSJHK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMB3UGI5H5RCFRU6OGRPMNUCNLJGEN7Y/https://security.gentoo.org/glsa/202006-01https://security.netapp.com/advisory/ntap-20200619-0004/https://usn.ubuntu.com/4384-1/https://www.debian.org/security/2020/dsa-4697
2020-06-04
Published