VDB

CVE-2017-14032

CVE-2017-14032 PUBLISHED

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

EPSS 0.27% · 51.0th percentile

Risk Scores

EPSS Score
0.27%
51.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSmbedtls2.2.1-2, 2.1.2-1, 2.2.1-2ubuntu0.1

Timeline

  • Aug 30, 2017 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 27, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
  • Jan 7, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›