ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.
CVSS Details
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mbedtls2Upgrade mbedtlsUpgrade mbedtls3 | Aug 22, 2024 | Aug 30, 2017 |
| Debian | — | Upgrade mbedtls | Dec 5, 2017 | Aug 30, 2017 |
| Suse | — | Upgrade mbedtls-develUpgrade libmbedtls9 | Oct 18, 2017 | Aug 30, 2017 |
| Ubuntu | — | Upgrade mbedtls | Nov 19, 2024 | Aug 30, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub