CVE-2020-36363: Amazon Cloudfront

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers.

Affected products

  • Amazon Amazon Cloudfront: version 1.2_2019 only

Published 2021-08-12. Last modified 2026-06-17.