Lucene search

K
nvd[email protected]NVD:CVE-2017-14032
HistoryAug 30, 2017 - 8:29 p.m.

CVE-2017-14032

2017-08-3020:29:00
CWE-287
web.nvd.nist.gov
12

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.007

Percentile

80.6%

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

Affected configurations

Nvd
Node
armmbed_tlsMatch1.3.10
OR
armmbed_tlsMatch1.3.11
OR
armmbed_tlsMatch1.3.12
OR
armmbed_tlsMatch1.3.13
OR
armmbed_tlsMatch1.3.14
OR
armmbed_tlsMatch1.3.15
OR
armmbed_tlsMatch1.3.16
OR
armmbed_tlsMatch1.3.17
OR
armmbed_tlsMatch1.3.18
OR
armmbed_tlsMatch1.3.19
OR
armmbed_tlsMatch1.3.20
OR
armmbed_tlsMatch1.3.21
OR
armmbed_tlsMatch2.0.0
OR
armmbed_tlsMatch2.1.0
OR
armmbed_tlsMatch2.1.1
OR
armmbed_tlsMatch2.1.2
OR
armmbed_tlsMatch2.1.3
OR
armmbed_tlsMatch2.1.4
OR
armmbed_tlsMatch2.1.5
OR
armmbed_tlsMatch2.1.6
OR
armmbed_tlsMatch2.1.7
OR
armmbed_tlsMatch2.1.8
OR
armmbed_tlsMatch2.1.9
OR
armmbed_tlsMatch2.2.0
OR
armmbed_tlsMatch2.2.1
OR
armmbed_tlsMatch2.3.0
OR
armmbed_tlsMatch2.4.0
OR
armmbed_tlsMatch2.4.2
OR
armmbed_tlsMatch2.5.1
OR
armmbed_tlsMatch2.6.2
VendorProductVersionCPE
armmbed_tls1.3.10cpe:2.3:a:arm:mbed_tls:1.3.10:*:*:*:*:*:*:*
armmbed_tls1.3.11cpe:2.3:a:arm:mbed_tls:1.3.11:*:*:*:*:*:*:*
armmbed_tls1.3.12cpe:2.3:a:arm:mbed_tls:1.3.12:*:*:*:*:*:*:*
armmbed_tls1.3.13cpe:2.3:a:arm:mbed_tls:1.3.13:*:*:*:*:*:*:*
armmbed_tls1.3.14cpe:2.3:a:arm:mbed_tls:1.3.14:*:*:*:*:*:*:*
armmbed_tls1.3.15cpe:2.3:a:arm:mbed_tls:1.3.15:*:*:*:*:*:*:*
armmbed_tls1.3.16cpe:2.3:a:arm:mbed_tls:1.3.16:*:*:*:*:*:*:*
armmbed_tls1.3.17cpe:2.3:a:arm:mbed_tls:1.3.17:*:*:*:*:*:*:*
armmbed_tls1.3.18cpe:2.3:a:arm:mbed_tls:1.3.18:*:*:*:*:*:*:*
armmbed_tls1.3.19cpe:2.3:a:arm:mbed_tls:1.3.19:*:*:*:*:*:*:*
Rows per page:
1-10 of 301

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.007

Percentile

80.6%