Vulnerabilities
Vulnerable Software
Arm:  >> Mbed Tls  >> 2.1.14  Security Vulnerabilities
ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RSA-signed ones should be.. This attack appear to be exploitable via Peers negotiate a TLS-ECDH-RSA-* ciphersuite. Any of the peers can then provide an ECDSA-signed certificate, when only an RSA-signed one should be accepted..
CVSS Score
7.5
EPSS Score
0.001
Published
2018-06-26
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.
CVSS Score
9.8
EPSS Score
0.006
Published
2018-02-14


Contact Us

Shodan ® - All rights reserved