An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Arm
Subscribe
|
Mbed Tls
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Siemens
Subscribe
|
Logo\! Cmr2020
Subscribe
Logo\! Cmr2020 Firmware
Subscribe
Logo\! Cmr2040
Subscribe
Logo\! Cmr2040 Firmware
Subscribe
Simatic Rtu3000c
Subscribe
Simatic Rtu3000c Firmware
Subscribe
Simatic Rtu3030c
Subscribe
Simatic Rtu3030c Firmware
Subscribe
Simatic Rtu3031c
Subscribe
Simatic Rtu3031c Firmware
Subscribe
Simatic Rtu3041c
Subscribe
Simatic Rtu3041c Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2826-1 | mbedtls security update |
Debian DLA |
DLA-3249-1 | mbedtls security update |
EUVD |
EUVD-2020-23964 | An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:30:07.313Z
Reserved: 2021-08-23T00:00:00
Link: CVE-2020-36478
No data.
Status : Modified
Published: 2021-08-23T02:15:07.097
Modified: 2024-11-21T05:29:38.247
Link: CVE-2020-36478
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD