CVE-2020-36475

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/08/2021
Last modified:
11/01/2023

Description

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* 2.7.18 (excluding)
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* 2.8.0 (including) 2.16.9 (excluding)
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* 2.17.0 (including) 2.25.0 (excluding)
cpe:2.3:o:siemens:logo\!_cmr2020_firmware:*:*:*:*:*:*:*:* 2.2 (excluding)
cpe:2.3:h:siemens:logo\!_cmr2020:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:logo\!_cmr2040_firmware:*:*:*:*:*:*:*:* 2.2 (excluding)
cpe:2.3:h:siemens:logo\!_cmr2040:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rtu3031c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3031c:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rtu3041c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3041c:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rtu3030c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3030c:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rtu3000c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rtu3000c:-:*:*:*:*:*:*:*