Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6v28-r64j-r4w6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

EPSS

Процентиль: 23%
0.00075
Низкий

8.1 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

CVSS3: 8.1
nvd
больше 8 лет назад

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

CVSS3: 8.1
debian
больше 8 лет назад

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentic ...

EPSS

Процентиль: 23%
0.00075
Низкий

8.1 High

CVSS3

Дефекты

CWE-287