CVE-2020-36478: Arm Mbed TLS
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
Affected products
- Arm Mbed TLS: before 2.7.18 (fixed in 2.7.18); from 2.8.0, before 2.16.9 (fixed in 2.16.9); from 2.17.0, before 2.25.0 (fixed in 2.25.0)
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Siemens Logo! CMR2020 Firmware: before 2.2 (fixed in 2.2)
- Siemens Logo! CMR2040 Firmware: before 2.2 (fixed in 2.2)
- Siemens SIMATIC RTU3000C Firmware: any version
- Siemens SIMATIC RTU3030C Firmware: any version
- Siemens SIMATIC RTU3031C Firmware: any version
- Siemens SIMATIC RTU3041C Firmware: any version
Published 2021-08-23. Last modified 2026-06-17.