VDB

CVE-2018-1000520

CVE-2018-1000520 PUBLISHED

ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RSA-signed ones should be.. This attack appear to be exploitable via Peers negotiate a TLS-ECDH-RSA-* ciphersuite. Any of the peers can then provide an ECDSA-signed certificate, when only an RSA-signed one should be accepted..

EPSS 0.17% · 37.7th percentile

Risk Scores

EPSS Score
0.17%
37.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSmbedtls0, 2.16.2-1, 2.16.3-1
Ubuntu:25.10mbedtls3.6.2-3ubuntu1, 0
Ubuntu:18.04:LTSmbedtls2.7.0-2, 0, 2.5.1-1ubuntu1
Ubuntu:24.04:LTSmbedtls0, 2.28.3-1, 2.28.7-1ubuntu1
Ubuntu:22.04:LTSmbedtls0, 2.16.11-0.3, 2.16.9-0.1ubuntu1
Ubuntu:16.04:LTSmbedtls2.2.1-1, 2.2.0-1, 2.1.2-1

Exploit Intelligence

Timeline

  • Jun 26, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›