First published: Tue Jun 26 2018(Updated: )
ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RSA-signed ones should be.. This attack appear to be exploitable via Peers negotiate a TLS-ECDH-RSA-* ciphersuite. Any of the peers can then provide an ECDSA-signed certificate, when only an RSA-signed one should be accepted..
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ARM mbed TLS | <=2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-1000520.
The severity of CVE-2018-1000520 is high with a severity value of 7.5.
The ARM mbedTLS version 2.7.0 and earlier is affected by CVE-2018-1000520.
CVE-2018-1000520 is a vulnerability in mbedtls_ssl_get_verify_result() function of ARM mbedTLS version 2.7.0 and earlier that allows incorrectly signed certificates to be accepted.
Yes, there is a fix available for CVE-2018-1000520. Please refer to the provided reference link for more information.