An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
References
Configurations
History
No history.
Information
Published : 2021-07-19 17:15
Updated : 2024-11-21 05:29
NVD link : CVE-2020-36425
Mitre link : CVE-2020-36425
CVE.ORG link : CVE-2020-36425
JSON object : View
Products Affected
debian
- debian_linux
arm
- mbed_tls
CWE
CWE-295
Improper Certificate Validation