CVE-2020-36425
19.07.2021, 17:15
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.Enginsight
Vendor | Product | Version |
---|---|---|
arm | mbed_tls | 𝑥 < 2.7.17 |
arm | mbed_tls | 2.8.0 ≤ 𝑥 < 2.16.8 |
arm | mbed_tls | 2.17.0 ≤ 𝑥 < 2.24.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References