HIGH · 7.4

CVE-2020-13777

GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is...

Vulnerability Description

GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
GnuGnutls>= 3.6.0, < 3.6.14
FedoraprojectFedora31
CanonicalUbuntu Linux19.10
DebianDebian Linux10.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-13777?

CVE-2020-13777 is a vulnerability with a CVSS score of 7.4 (HIGH). GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is...

How severe is CVE-2020-13777?

CVE-2020-13777 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-13777?

Check the references section above for vendor advisories and patch information. Affected products include: Gnu Gnutls, Fedoraproject Fedora, Canonical Ubuntu Linux, Debian Debian Linux.