CVE-2020-36425: Medium severity mbed tls vulnerability
Published Jul 19, 2021
·Updated
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
Affected Software
4 affected components
Arm mbed TLS<2.7.17
Arm mbed TLS>=2.8.0<2.16.8
Arm mbed TLS>=2.17.0<2.24.0
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Jul 19, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 4, 2025
Data Sourced
via Microsoft·03:19 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-36425.
2
What is the severity of CVE-2020-36425?
The severity of CVE-2020-36425 is medium with a CVSS score of 5.3.
3
What software is affected by CVE-2020-36425?
The ARM mbed TLS versions up to 2.16.8, 2.17.0 to 2.24.0, and Debian Debian Linux 10.0 are affected by CVE-2020-36425.
4
What is the issue with Arm Mbed TLS before version 2.24.0?
Arm Mbed TLS before version 2.24.0 incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL, which can be exploited by changing the local clock.
5
Are there any available fixes for CVE-2020-36425?
Yes, upgrading to Arm Mbed TLS version 2.24.0 or later resolves CVE-2020-36425.