CVE-2020-36478

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:logo\!_cmr2020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:logo\!_cmr2020:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:logo\!_cmr2040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:logo\!_cmr2040:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_rtu3031c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3031c:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_rtu3041c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3041c:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_rtu3030c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3030c:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_rtu3000c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3000c:-:*:*:*:*:*:*:*

Configuration 8 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

11 Jan 2023, 17:01

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
References (MLIST) https://lists.debian.org/debian-lts-announce/2022/12/msg00036.html - (MLIST) https://lists.debian.org/debian-lts-announce/2022/12/msg00036.html - Mailing List, Third Party Advisory

26 Dec 2022, 03:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2022/12/msg00036.html -

26 Nov 2021, 21:35

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
References (MLIST) https://lists.debian.org/debian-lts-announce/2021/11/msg00021.html - (MLIST) https://lists.debian.org/debian-lts-announce/2021/11/msg00021.html - Mailing List, Third Party Advisory

23 Nov 2021, 16:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2021/11/msg00021.html -

16 Sep 2021, 16:03

Type Values Removed Values Added
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-756638.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-756638.pdf - Patch, Third Party Advisory
CPE cpe:2.3:o:siemens:simatic_rtu3030c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:logo\!_cmr2040:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:logo\!_cmr2020:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rtu3031c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:logo\!_cmr2020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:logo\!_cmr2040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rtu3041c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3041c:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3030c:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3000c:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3031c:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rtu3000c_firmware:*:*:*:*:*:*:*:*

14 Sep 2021, 13:15

Type Values Removed Values Added
References
  • (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-756638.pdf -

28 Aug 2021, 01:13

Type Values Removed Values Added
CPE cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
References (MISC) https://github.com/ARMmbed/mbedtls/releases/tag/v2.25.0 - (MISC) https://github.com/ARMmbed/mbedtls/releases/tag/v2.25.0 - Release Notes, Third Party Advisory
References (MISC) https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.9 - (MISC) https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.9 - Release Notes, Third Party Advisory
References (MISC) https://github.com/ARMmbed/mbedtls/issues/3629 - (MISC) https://github.com/ARMmbed/mbedtls/issues/3629 - Exploit, Third Party Advisory
References (MISC) https://github.com/ARMmbed/mbedtls/releases/tag/v2.7.18 - (MISC) https://github.com/ARMmbed/mbedtls/releases/tag/v2.7.18 - Release Notes, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-295

23 Aug 2021, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-23 02:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-36478

Mitre link : CVE-2020-36478

CVE.ORG link : CVE-2020-36478


JSON object : View

Products Affected

debian

  • debian_linux

siemens

  • simatic_rtu3000c_firmware
  • simatic_rtu3031c_firmware
  • simatic_rtu3000c
  • logo\!_cmr2040_firmware
  • simatic_rtu3030c
  • simatic_rtu3030c_firmware
  • logo\!_cmr2020
  • simatic_rtu3031c
  • logo\!_cmr2020_firmware
  • simatic_rtu3041c_firmware
  • logo\!_cmr2040
  • simatic_rtu3041c

arm

  • mbed_tls
CWE
CWE-295

Improper Certificate Validation