CVE-2020-36363: Critical severity amazon cloudfront vulnerability
Published Aug 12, 2021
·Updated
Amazon AWS CloudFront TLSv1.22019 allows TLSECDHERSAWITHAES128CBCSHA256 and TLSECDHERSAWITHAES256CBCSHA384, which some entities consider to be weak ciphers.
Affected Software
1 affected component
Amazon Amazon Cloudfront=1.2_2019
Event History
Aug 12, 2021
CVE Published
via MITRE·09:13 PM
Data Sourced
via MITRE·09:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36363?
CVE-2020-36363 is considered to have a medium severity due to the use of weak cryptographic ciphers in Amazon AWS CloudFront.
2
How do I fix CVE-2020-36363?
To mitigate CVE-2020-36363, configure your Amazon CloudFront distribution to use stronger TLS ciphers and protocols.
3
What vulnerable components are affected by CVE-2020-36363?
The vulnerable component affected by CVE-2020-36363 is Amazon CloudFront version 1.2_2019.
4
What are the implications of exploiting CVE-2020-36363?
Exploiting CVE-2020-36363 could allow attackers to compromise encrypted traffic due to the use of weak ciphers.
5
Is there a workaround for CVE-2020-36363?
A workaround for CVE-2020-36363 is to disable weak ciphers in your AWS CloudFront configuration until a fix can be applied.