Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-71450
HistoryAug 25, 2021 - 12:00 a.m.

ARM mbed TLS Trust Management Issue Vulnerability

2021-08-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
arm mbed tls
trust management issue
security vulnerability
encryption
certificate validation

EPSS

0.003

Percentile

71.2%

ARM mbed TLS is a product from ARM UK that provides secure communication and encryption for mbed products. ARM mbed TLS has a security vulnerability that stems from the fact that the null algorithm parameter term is the same as the real array (of size 0) and therefore the certificate is considered valid. However, if the parameters do not match in any respect, the certificate is considered invalid. No detailed vulnerability details are currently available.