CVE-2020-36425 — Improper Certificate Validation in ARM Mbed TLS
Severity
5.3MEDIUMNVD
EPSS
0.6%
top 30.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 19
Latest updateMay 24
Description
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages2 packages
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
3📋Vendor Advisories
2Microsoft▶
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can e↗2021-07-13
Debian▶
CVE-2020-36425: mbedtls - An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a rev...↗2020