HIGH · 7.5

CVE-2020-36478

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certific...

Vulnerability Description

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
ArmMbed Tls< 2.7.18
SiemensLogo\! Cmr2020 Firmware< 2.2
SiemensLogo\! Cmr2020-
SiemensLogo\! Cmr2040 Firmware< 2.2
SiemensLogo\! Cmr2040-
SiemensSimatic Rtu3031C FirmwareAll versions
SiemensSimatic Rtu3031C-
SiemensSimatic Rtu3041C FirmwareAll versions
SiemensSimatic Rtu3041C-
SiemensSimatic Rtu3030C FirmwareAll versions
SiemensSimatic Rtu3030C-
SiemensSimatic Rtu3000C FirmwareAll versions
SiemensSimatic Rtu3000C-
DebianDebian Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-36478?

CVE-2020-36478 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certific...

How severe is CVE-2020-36478?

CVE-2020-36478 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-36478?

Check the references section above for vendor advisories and patch information. Affected products include: Arm Mbed Tls, Siemens Logo\! Cmr2020 Firmware, Siemens Logo\! Cmr2020, Siemens Logo\! Cmr2040 Firmware, Siemens Logo\! Cmr2040.