CVE-2020-36475
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/08/2021
Last modified:
11/01/2023
Description
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | 2.7.18 (excluding) | |
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | 2.8.0 (including) | 2.16.9 (excluding) |
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | 2.17.0 (including) | 2.25.0 (excluding) |
cpe:2.3:o:siemens:logo\!_cmr2020_firmware:*:*:*:*:*:*:*:* | 2.2 (excluding) | |
cpe:2.3:h:siemens:logo\!_cmr2020:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:siemens:logo\!_cmr2040_firmware:*:*:*:*:*:*:*:* | 2.2 (excluding) | |
cpe:2.3:h:siemens:logo\!_cmr2040:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:siemens:simatic_rtu3031c_firmware:*:*:*:*:*:*:*:* | ||
cpe:2.3:h:siemens:simatic_rtu3031c:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:siemens:simatic_rtu3041c_firmware:*:*:*:*:*:*:*:* | ||
cpe:2.3:h:siemens:simatic_rtu3041c:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:siemens:simatic_rtu3030c_firmware:*:*:*:*:*:*:*:* | ||
cpe:2.3:h:siemens:simatic_rtu3030c:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:siemens:simatic_rtu3000c_firmware:*:*:*:*:*:*:*:* | ||
cpe:2.3:h:siemens:simatic_rtu3000c:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://cert-portal.siemens.com/productcert/pdf/ssa-756638.pdf
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.9
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.25.0
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.7.18
- https://lists.debian.org/debian-lts-announce/2021/11/msg00021.html
- https://lists.debian.org/debian-lts-announce/2022/12/msg00036.html