5.8
CVSSv2

CVE-2020-13777

Published: 04/06/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 518
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

GnuTLS 3.6.x prior to 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls

fedoraproject fedora 31

fedoraproject fedora 32

canonical ubuntu linux 19.10

canonical ubuntu linux 20.04

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #962289 gnutls28: CVE-2020-13777: session resumption works without master key allowing MITM Package: src:gnutls28; Maintainer for src:gnutls28 is Debian GnuTLS Maintainers <pkg-gnutls-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 5 Jun 2020 1 ...
GnuTLS could be made to expose sensitive information ...
Synopsis Important: gnutls security update Type/Severity Security Advisory: Important Topic An update for gnutls is now available for Red Hat Enterprise Linux 81 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Synopsis Important: gnutls security update Type/Severity Security Advisory: Important Topic An update for gnutls is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, w ...
Краткий обзор Important: gnutls security update Тип/Серьезность Security Advisory: Important Тема An update for gnutls is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact ...
Synopsis Moderate: Red Hat Quay v331 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Quay 33Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Important: Container-native Virtualization security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Virtualization release 240 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Securi ...
A flaw was reported in the TLS session ticket key construction in GnuTLS, a library implementing the TLS and SSL protocols The flaw caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret, allowing a man-in-the-middle attacker to bypass authentication in TLS 13 and recover previo ...
GnuTLS 36x before 3614 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 12, and an authentication bypass in TLS 13) The earliest affected version is 364 (2018-09-24) because of an error in a 2018-09-18 commit Until the first key rotation, the TLS server always uses wrong data in place of an enc ...

Github Repositories

PoC TLS13 CVE-2020-13777 The purpose of this PoC This PoC and related article were created to apply for the project "Challenge CVE-2020-13777" CVE-2020-13777 is a GnuTLS vulnerability whose patch is widely distributed This PoC aims to contribute to improving the information security literacy of people involved in the information and communications industry By wide

Some of my personal automation shell scripts.

Shell-Scripts Some of my personal automation shell scripts Details of all scripts Sub-Enumsh Syntax --> /Sub-Enumsh < filename containing all domains > This script takes a file containing all domains and enumerate subdomains for each of them using multiple tools as Subfinder , Assetfinder , Amass Then after sorting them it check for alive subdomains a

Zeek script to detect servers vulnerable to CVE-2020-13777

Zeek test script for CVE-2020-13777 This script performs a simple test to check if a server is potentially vulnerable to CVE-2020-13777 CVE-2020-13777 causes GnuTLS to create unencrypted session tickets This seems to be detectable by checking gnutls sets the key_name to zero - for which it uses the first 16 bytes of the session-ticket This script checks if: A server sends a

A simple to use TLS server library for Linux

tlsserver - a simple to use TLS server library for Linux tlsserver is a TLS server library that can use OpenSSL or GnuTLS as a backend As a difference to other libraries all mentioned backends can be enabled at compile time and backend selection is possibe at runtime The libtlsserverso shared library as well as the required tlsserverh header file are licensed LGPLv21+, eve

Challange CVE-2020-13777

Chanllenge CVE-2020-13777 Try to prove if TLS 13 MITM is possible and decrypt 0-RTT early data in pcap here (Server: 19216810023:5556) See jovi0608hatenablogcom/entry/2020/06/13/104905 and CVE-2020-13777 for details

CSI SIEM

Malcolm CSI-SIEM using Malcolm is a powerful network traffic analysis tool suite designed with the following goals in mind: Easy to use – Malcolm accepts network traffic data in the form of full packet capture (PCAP) files and Zeek (formerly Bro) logs These artifacts can be uploaded via a simple browser-based interface or captured live and forwarded to Malcolm using li

Malcolm CSI-SIEM using Malcolm is a powerful network traffic analysis tool suite designed with the following goals in mind: Easy to use – Malcolm accepts network traffic data in the form of full packet capture (PCAP) files and Zeek (formerly Bro) logs These artifacts can be uploaded via a simple browser-based interface or captured live and forwarded to Malcolm using li

A collection of zeek detection scripts

Bro/Zeek Detection Script Collection A collection of bro/zeek detection scripts This is just a list Detection of techniques Mitre BZAR Detection of Long Connections Ransomware Filenames PingBack Cryptomining Detection of Vulnerabilities CVE-2020-0601 0xxon CVE-2020-1472 - Zerologon Corelight CVE-2020-12695 - CallStranger Corelight CVE-2020-13777 0xxon Threat I