CVE-2020-36475
23.08.2021, 02:15
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.Enginsight
Vendor | Product | Version |
---|---|---|
arm | mbed_tls | 𝑥 < 2.7.18 |
arm | mbed_tls | 2.8.0 ≤ 𝑥 < 2.16.9 |
arm | mbed_tls | 2.17.0 ≤ 𝑥 < 2.25.0 |
siemens | logo\!_cmr2020_firmware | 𝑥 < 2.2 |
siemens | logo\!_cmr2040_firmware | 𝑥 < 2.2 |
siemens | simatic_rtu3031c_firmware | * |
siemens | simatic_rtu3041c_firmware | * |
siemens | simatic_rtu3030c_firmware | * |
siemens | simatic_rtu3000c_firmware | * |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References