Vulnerability Description
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arm | Mbed Tls | 1.3.10 |
Related Weaknesses (CWE)
References
- http://www.debian.org/security/2017/dsa-3967
- https://bugs.debian.org/873557Issue TrackingPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/31458a18788b0cf0b722acda9bb2f2fe13a3fbIssue TrackingPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/d15795acd5074e0b44e71f7ede8bdfe1b48591Issue TrackingPatchThird Party Advisory
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-Vendor Advisory
- http://www.debian.org/security/2017/dsa-3967
- https://bugs.debian.org/873557Issue TrackingPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/31458a18788b0cf0b722acda9bb2f2fe13a3fbIssue TrackingPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/d15795acd5074e0b44e71f7ede8bdfe1b48591Issue TrackingPatchThird Party Advisory
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-Vendor Advisory
FAQ
What is CVE-2017-14032?
CVE-2017-14032 is a vulnerability with a CVSS score of 8.1 (HIGH). ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates....
How severe is CVE-2017-14032?
CVE-2017-14032 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14032?
Check the references section above for vendor advisories and patch information. Affected products include: Arm Mbed Tls.