First published: Mon Jul 19 2021(Updated: )
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ARM mbed TLS | <2.7.17 | |
ARM mbed TLS | >=2.8.0<2.16.8 | |
ARM mbed TLS | >=2.17.0<2.24.0 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2020-36425.
The severity of CVE-2020-36425 is medium with a CVSS score of 5.3.
The ARM mbed TLS versions up to 2.16.8, 2.17.0 to 2.24.0, and Debian Debian Linux 10.0 are affected by CVE-2020-36425.
Arm Mbed TLS before version 2.24.0 incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL, which can be exploited by changing the local clock.
Yes, upgrading to Arm Mbed TLS version 2.24.0 or later resolves CVE-2020-36425.