Vulnerability Details CVE-2017-14032
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.8%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
Products affected by CVE-2017-14032
-
cpe:2.3:a:arm:mbed_tls:1.3.10
-
cpe:2.3:a:arm:mbed_tls:1.3.11
-
cpe:2.3:a:arm:mbed_tls:1.3.12
-
cpe:2.3:a:arm:mbed_tls:1.3.13
-
cpe:2.3:a:arm:mbed_tls:1.3.14
-
cpe:2.3:a:arm:mbed_tls:1.3.15
-
cpe:2.3:a:arm:mbed_tls:1.3.16
-
cpe:2.3:a:arm:mbed_tls:1.3.17
-
cpe:2.3:a:arm:mbed_tls:1.3.18
-
cpe:2.3:a:arm:mbed_tls:1.3.19
-
cpe:2.3:a:arm:mbed_tls:1.3.20
-
cpe:2.3:a:arm:mbed_tls:1.3.21
-
cpe:2.3:a:arm:mbed_tls:2.0.0
-
cpe:2.3:a:arm:mbed_tls:2.1.0
-
cpe:2.3:a:arm:mbed_tls:2.1.1
-
cpe:2.3:a:arm:mbed_tls:2.1.2
-
cpe:2.3:a:arm:mbed_tls:2.1.3
-
cpe:2.3:a:arm:mbed_tls:2.1.4
-
cpe:2.3:a:arm:mbed_tls:2.1.5
-
cpe:2.3:a:arm:mbed_tls:2.1.6
-
cpe:2.3:a:arm:mbed_tls:2.1.7
-
cpe:2.3:a:arm:mbed_tls:2.1.8
-
cpe:2.3:a:arm:mbed_tls:2.1.9
-
cpe:2.3:a:arm:mbed_tls:2.2.0
-
cpe:2.3:a:arm:mbed_tls:2.2.1
-
cpe:2.3:a:arm:mbed_tls:2.3.0
-
cpe:2.3:a:arm:mbed_tls:2.4.0
-
cpe:2.3:a:arm:mbed_tls:2.4.2
-
cpe:2.3:a:arm:mbed_tls:2.5.1
-
cpe:2.3:a:arm:mbed_tls:2.6.2