6.8
CVSSv2

CVE-2017-14032

Published: 30/08/2017 Updated: 08/11/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

ARM mbed TLS prior to 1.3.21 and 2.x prior to 2.1.9, if optional authentication is configured, allows remote malicious users to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arm mbed tls 1.3.12

arm mbed tls 1.3.13

arm mbed tls 1.3.21

arm mbed tls 2.1.9

arm mbed tls 1.3.10

arm mbed tls 1.3.11

arm mbed tls 1.3.18

arm mbed tls 1.3.19

arm mbed tls 2.4.2

arm mbed tls 2.5.1

arm mbed tls 2.1.2

arm mbed tls 2.1.3

arm mbed tls 2.6.2

arm mbed tls 2.1.7

arm mbed tls 2.1.4

arm mbed tls 2.1.5

arm mbed tls 1.3.16

arm mbed tls 1.3.17

arm mbed tls 2.3.0

arm mbed tls 2.4.0

arm mbed tls 2.1.0

arm mbed tls 2.1.1

arm mbed tls 1.3.14

arm mbed tls 1.3.15

arm mbed tls 2.2.0

arm mbed tls 2.2.1

arm mbed tls 2.1.8

arm mbed tls 1.3.20

arm mbed tls 2.0.0

arm mbed tls 2.1.6

Vendor Advisories

Debian Bug report logs - #873557 mbedtls: CVE-2017-14032: authentication bypass Package: src:mbedtls; Maintainer for src:mbedtls is James Cowgill <jcowgill@debianorg>; Reported by: James Cowgill <jcowgill@debianorg> Date: Mon, 28 Aug 2017 23:12:02 UTC Severity: grave Tags: fixed-upstream, security, upstream Found ...
An authentication bypass vulnerability was discovered in mbed TLS, a lightweight crypto and SSL/TLS library, when the authentication mode is configured as optional A remote attacker can take advantage of this flaw to mount a man-in-the-middle attack and impersonate an intended peer via an X509 certificate chain with many intermediates For the st ...