Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-36478

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
References
Products affected by CVE-2020-36478
  • Arm » Mbed Tls » Version: N/A
    cpe:2.3:a:arm:mbed_tls:-
  • Arm » Mbed Tls » Version: 1.3.0
    cpe:2.3:a:arm:mbed_tls:1.3.0
  • Arm » Mbed Tls » Version: 1.3.1
    cpe:2.3:a:arm:mbed_tls:1.3.1
  • Arm » Mbed Tls » Version: 1.3.10
    cpe:2.3:a:arm:mbed_tls:1.3.10
  • Arm » Mbed Tls » Version: 1.3.11
    cpe:2.3:a:arm:mbed_tls:1.3.11
  • Arm » Mbed Tls » Version: 1.3.12
    cpe:2.3:a:arm:mbed_tls:1.3.12
  • Arm » Mbed Tls » Version: 1.3.13
    cpe:2.3:a:arm:mbed_tls:1.3.13
  • Arm » Mbed Tls » Version: 1.3.14
    cpe:2.3:a:arm:mbed_tls:1.3.14
  • Arm » Mbed Tls » Version: 1.3.15
    cpe:2.3:a:arm:mbed_tls:1.3.15
  • Arm » Mbed Tls » Version: 1.3.16
    cpe:2.3:a:arm:mbed_tls:1.3.16
  • Arm » Mbed Tls » Version: 1.3.17
    cpe:2.3:a:arm:mbed_tls:1.3.17
  • Arm » Mbed Tls » Version: 1.3.18
    cpe:2.3:a:arm:mbed_tls:1.3.18
  • Arm » Mbed Tls » Version: 1.3.19
    cpe:2.3:a:arm:mbed_tls:1.3.19
  • Arm » Mbed Tls » Version: 1.3.2
    cpe:2.3:a:arm:mbed_tls:1.3.2
  • Arm » Mbed Tls » Version: 1.3.20
    cpe:2.3:a:arm:mbed_tls:1.3.20
  • Arm » Mbed Tls » Version: 1.3.21
    cpe:2.3:a:arm:mbed_tls:1.3.21
  • Arm » Mbed Tls » Version: 1.3.22
    cpe:2.3:a:arm:mbed_tls:1.3.22
  • Arm » Mbed Tls » Version: 1.3.3
    cpe:2.3:a:arm:mbed_tls:1.3.3
  • Arm » Mbed Tls » Version: 1.3.4
    cpe:2.3:a:arm:mbed_tls:1.3.4
  • Arm » Mbed Tls » Version: 1.3.5
    cpe:2.3:a:arm:mbed_tls:1.3.5
  • Arm » Mbed Tls » Version: 1.3.6
    cpe:2.3:a:arm:mbed_tls:1.3.6
  • Arm » Mbed Tls » Version: 1.3.7
    cpe:2.3:a:arm:mbed_tls:1.3.7
  • Arm » Mbed Tls » Version: 1.3.8
    cpe:2.3:a:arm:mbed_tls:1.3.8
  • Arm » Mbed Tls » Version: 1.3.9
    cpe:2.3:a:arm:mbed_tls:1.3.9
  • Arm » Mbed Tls » Version: 2.0.0
    cpe:2.3:a:arm:mbed_tls:2.0.0
  • Arm » Mbed Tls » Version: 2.1.0
    cpe:2.3:a:arm:mbed_tls:2.1.0
  • Arm » Mbed Tls » Version: 2.1.1
    cpe:2.3:a:arm:mbed_tls:2.1.1
  • Arm » Mbed Tls » Version: 2.1.10
    cpe:2.3:a:arm:mbed_tls:2.1.10
  • Arm » Mbed Tls » Version: 2.1.11
    cpe:2.3:a:arm:mbed_tls:2.1.11
  • Arm » Mbed Tls » Version: 2.1.12
    cpe:2.3:a:arm:mbed_tls:2.1.12
  • Arm » Mbed Tls » Version: 2.1.13
    cpe:2.3:a:arm:mbed_tls:2.1.13
  • Arm » Mbed Tls » Version: 2.1.14
    cpe:2.3:a:arm:mbed_tls:2.1.14
  • Arm » Mbed Tls » Version: 2.1.15
    cpe:2.3:a:arm:mbed_tls:2.1.15
  • Arm » Mbed Tls » Version: 2.1.16
    cpe:2.3:a:arm:mbed_tls:2.1.16
  • Arm » Mbed Tls » Version: 2.1.17
    cpe:2.3:a:arm:mbed_tls:2.1.17
  • Arm » Mbed Tls » Version: 2.1.18
    cpe:2.3:a:arm:mbed_tls:2.1.18
  • Arm » Mbed Tls » Version: 2.1.2
    cpe:2.3:a:arm:mbed_tls:2.1.2
  • Arm » Mbed Tls » Version: 2.1.3
    cpe:2.3:a:arm:mbed_tls:2.1.3
  • Arm » Mbed Tls » Version: 2.1.4
    cpe:2.3:a:arm:mbed_tls:2.1.4
  • Arm » Mbed Tls » Version: 2.1.5
    cpe:2.3:a:arm:mbed_tls:2.1.5
  • Arm » Mbed Tls » Version: 2.1.6
    cpe:2.3:a:arm:mbed_tls:2.1.6
  • Arm » Mbed Tls » Version: 2.1.7
    cpe:2.3:a:arm:mbed_tls:2.1.7
  • Arm » Mbed Tls » Version: 2.1.8
    cpe:2.3:a:arm:mbed_tls:2.1.8
  • Arm » Mbed Tls » Version: 2.1.9
    cpe:2.3:a:arm:mbed_tls:2.1.9
  • Arm » Mbed Tls » Version: 2.10.0
    cpe:2.3:a:arm:mbed_tls:2.10.0
  • Arm » Mbed Tls » Version: 2.11.0
    cpe:2.3:a:arm:mbed_tls:2.11.0
  • Arm » Mbed Tls » Version: 2.12.0
    cpe:2.3:a:arm:mbed_tls:2.12.0
  • Arm » Mbed Tls » Version: 2.13.0
    cpe:2.3:a:arm:mbed_tls:2.13.0
  • Arm » Mbed Tls » Version: 2.13.1
    cpe:2.3:a:arm:mbed_tls:2.13.1
  • Arm » Mbed Tls » Version: 2.14.0
    cpe:2.3:a:arm:mbed_tls:2.14.0
  • Arm » Mbed Tls » Version: 2.14.1
    cpe:2.3:a:arm:mbed_tls:2.14.1
  • Arm » Mbed Tls » Version: 2.15.0
    cpe:2.3:a:arm:mbed_tls:2.15.0
  • Arm » Mbed Tls » Version: 2.15.1
    cpe:2.3:a:arm:mbed_tls:2.15.1
  • Arm » Mbed Tls » Version: 2.16.0
    cpe:2.3:a:arm:mbed_tls:2.16.0
  • Arm » Mbed Tls » Version: 2.16.1
    cpe:2.3:a:arm:mbed_tls:2.16.1
  • Arm » Mbed Tls » Version: 2.16.2
    cpe:2.3:a:arm:mbed_tls:2.16.2
  • Arm » Mbed Tls » Version: 2.16.3
    cpe:2.3:a:arm:mbed_tls:2.16.3
  • Arm » Mbed Tls » Version: 2.16.4
    cpe:2.3:a:arm:mbed_tls:2.16.4
  • Arm » Mbed Tls » Version: 2.16.5
    cpe:2.3:a:arm:mbed_tls:2.16.5
  • Arm » Mbed Tls » Version: 2.16.6
    cpe:2.3:a:arm:mbed_tls:2.16.6
  • Arm » Mbed Tls » Version: 2.16.7
    cpe:2.3:a:arm:mbed_tls:2.16.7
  • Arm » Mbed Tls » Version: 2.16.8
    cpe:2.3:a:arm:mbed_tls:2.16.8
  • Arm » Mbed Tls » Version: 2.17.0
    cpe:2.3:a:arm:mbed_tls:2.17.0
  • Arm » Mbed Tls » Version: 2.18.0
    cpe:2.3:a:arm:mbed_tls:2.18.0
  • Arm » Mbed Tls » Version: 2.18.1
    cpe:2.3:a:arm:mbed_tls:2.18.1
  • Arm » Mbed Tls » Version: 2.19.0
    cpe:2.3:a:arm:mbed_tls:2.19.0
  • Arm » Mbed Tls » Version: 2.19.1
    cpe:2.3:a:arm:mbed_tls:2.19.1
  • Arm » Mbed Tls » Version: 2.2.0
    cpe:2.3:a:arm:mbed_tls:2.2.0
  • Arm » Mbed Tls » Version: 2.2.1
    cpe:2.3:a:arm:mbed_tls:2.2.1
  • Arm » Mbed Tls » Version: 2.2.2
    cpe:2.3:a:arm:mbed_tls:2.2.2
  • Arm » Mbed Tls » Version: 2.2.3
    cpe:2.3:a:arm:mbed_tls:2.2.3
  • Arm » Mbed Tls » Version: 2.20.0
    cpe:2.3:a:arm:mbed_tls:2.20.0
  • Arm » Mbed Tls » Version: 2.21.0
    cpe:2.3:a:arm:mbed_tls:2.21.0
  • Arm » Mbed Tls » Version: 2.22.0
    cpe:2.3:a:arm:mbed_tls:2.22.0
  • Arm » Mbed Tls » Version: 2.23.0
    cpe:2.3:a:arm:mbed_tls:2.23.0
  • Arm » Mbed Tls » Version: 2.24.0
    cpe:2.3:a:arm:mbed_tls:2.24.0
  • Arm » Mbed Tls » Version: 2.3.0
    cpe:2.3:a:arm:mbed_tls:2.3.0
  • Arm » Mbed Tls » Version: 2.3.1
    cpe:2.3:a:arm:mbed_tls:2.3.1
  • Arm » Mbed Tls » Version: 2.3.2
    cpe:2.3:a:arm:mbed_tls:2.3.2
  • Arm » Mbed Tls » Version: 2.4.0
    cpe:2.3:a:arm:mbed_tls:2.4.0
  • Arm » Mbed Tls » Version: 2.4.1
    cpe:2.3:a:arm:mbed_tls:2.4.1
  • Arm » Mbed Tls » Version: 2.4.2
    cpe:2.3:a:arm:mbed_tls:2.4.2
  • Arm » Mbed Tls » Version: 2.5.0
    cpe:2.3:a:arm:mbed_tls:2.5.0
  • Arm » Mbed Tls » Version: 2.5.1
    cpe:2.3:a:arm:mbed_tls:2.5.1
  • Arm » Mbed Tls » Version: 2.6.0
    cpe:2.3:a:arm:mbed_tls:2.6.0
  • Arm » Mbed Tls » Version: 2.6.1
    cpe:2.3:a:arm:mbed_tls:2.6.1
  • Arm » Mbed Tls » Version: 2.7.0
    cpe:2.3:a:arm:mbed_tls:2.7.0
  • Arm » Mbed Tls » Version: 2.7.1
    cpe:2.3:a:arm:mbed_tls:2.7.1
  • Arm » Mbed Tls » Version: 2.7.10
    cpe:2.3:a:arm:mbed_tls:2.7.10
  • Arm » Mbed Tls » Version: 2.7.11
    cpe:2.3:a:arm:mbed_tls:2.7.11
  • Arm » Mbed Tls » Version: 2.7.12
    cpe:2.3:a:arm:mbed_tls:2.7.12
  • Arm » Mbed Tls » Version: 2.7.13
    cpe:2.3:a:arm:mbed_tls:2.7.13
  • Arm » Mbed Tls » Version: 2.7.14
    cpe:2.3:a:arm:mbed_tls:2.7.14
  • Arm » Mbed Tls » Version: 2.7.15
    cpe:2.3:a:arm:mbed_tls:2.7.15
  • Arm » Mbed Tls » Version: 2.7.16
    cpe:2.3:a:arm:mbed_tls:2.7.16
  • Arm » Mbed Tls » Version: 2.7.17
    cpe:2.3:a:arm:mbed_tls:2.7.17
  • Arm » Mbed Tls » Version: 2.7.2
    cpe:2.3:a:arm:mbed_tls:2.7.2
  • Arm » Mbed Tls » Version: 2.7.3
    cpe:2.3:a:arm:mbed_tls:2.7.3
  • Arm » Mbed Tls » Version: 2.7.4
    cpe:2.3:a:arm:mbed_tls:2.7.4
  • Arm » Mbed Tls » Version: 2.7.5
    cpe:2.3:a:arm:mbed_tls:2.7.5
  • Arm » Mbed Tls » Version: 2.7.6
    cpe:2.3:a:arm:mbed_tls:2.7.6
  • Arm » Mbed Tls » Version: 2.7.7
    cpe:2.3:a:arm:mbed_tls:2.7.7
  • Arm » Mbed Tls » Version: 2.7.8
    cpe:2.3:a:arm:mbed_tls:2.7.8
  • Arm » Mbed Tls » Version: 2.7.9
    cpe:2.3:a:arm:mbed_tls:2.7.9
  • Arm » Mbed Tls » Version: 2.8.0
    cpe:2.3:a:arm:mbed_tls:2.8.0
  • Arm » Mbed Tls » Version: 2.9.0
    cpe:2.3:a:arm:mbed_tls:2.9.0
  • Siemens » Logo! Cmr2020 » Version: N/A
    cpe:2.3:h:siemens:logo!_cmr2020:-
  • Siemens » Logo! Cmr2040 » Version: N/A
    cpe:2.3:h:siemens:logo!_cmr2040:-
  • Siemens » Simatic Rtu3000c » Version: N/A
    cpe:2.3:h:siemens:simatic_rtu3000c:-
  • Siemens » Simatic Rtu3030c » Version: N/A
    cpe:2.3:h:siemens:simatic_rtu3030c:-
  • Siemens » Simatic Rtu3031c » Version: N/A
    cpe:2.3:h:siemens:simatic_rtu3031c:-
  • Siemens » Simatic Rtu3041c » Version: N/A
    cpe:2.3:h:siemens:simatic_rtu3041c:-
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0
  • Siemens » Logo! Cmr2020 Firmware » Version: Any
    cpe:2.3:o:siemens:logo!_cmr2020_firmware:*
  • Siemens » Logo! Cmr2040 Firmware » Version: Any
    cpe:2.3:o:siemens:logo!_cmr2040_firmware:*
  • Siemens » Simatic Rtu3000c Firmware » Version: N/A
    cpe:2.3:o:siemens:simatic_rtu3000c_firmware:-
  • Siemens » Simatic Rtu3030c Firmware » Version: N/A
    cpe:2.3:o:siemens:simatic_rtu3030c_firmware:-
  • Siemens » Simatic Rtu3031c Firmware » Version: N/A
    cpe:2.3:o:siemens:simatic_rtu3031c_firmware:-
  • Siemens » Simatic Rtu3041c Firmware » Version: N/A
    cpe:2.3:o:siemens:simatic_rtu3041c_firmware:-


Contact Us

Shodan ® - All rights reserved