Description
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2826-1 | mbedtls security update |
Debian DLA |
DLA-3249-1 | mbedtls security update |
EUVD |
EUVD-2020-23964 | An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid. |
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Arm
Subscribe
Mbed Tls
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Siemens
Subscribe
Logo\! Cmr2020
Subscribe
Logo\! Cmr2020 Firmware
Subscribe
Logo\! Cmr2040
Subscribe
Logo\! Cmr2040 Firmware
Subscribe
Simatic Rtu3000c
Subscribe
Simatic Rtu3000c Firmware
Subscribe
Simatic Rtu3030c
Subscribe
Simatic Rtu3030c Firmware
Subscribe
Simatic Rtu3031c
Subscribe
Simatic Rtu3031c Firmware
Subscribe
Simatic Rtu3041c
Subscribe
Simatic Rtu3041c Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:30:07.313Z
Reserved: 2021-08-23T00:00:00.000Z
Link: CVE-2020-36478
No data.
Status : Modified
Published: 2021-08-23T02:15:07.097
Modified: 2024-11-21T05:29:38.247
Link: CVE-2020-36478
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD