Vulnerability Description
Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Amazon Cloudfront | 1.2_2019 |
Related Weaknesses (CWE)
References
- https://aws.amazon.com/about-aws/whats-new/2020/07/cloudfront-tls-security-policVendor Advisory
- https://stackoverflow.com/questions/62071604Third Party Advisory
- https://aws.amazon.com/about-aws/whats-new/2020/07/cloudfront-tls-security-policVendor Advisory
- https://stackoverflow.com/questions/62071604Third Party Advisory
FAQ
What is CVE-2020-36363?
CVE-2020-36363 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers.
How severe is CVE-2020-36363?
CVE-2020-36363 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-36363?
Check the references section above for vendor advisories and patch information. Affected products include: Amazon Amazon Cloudfront.