VDB
CVE-2020-36476
CVE-2020-36476
PUBLISHED
CVSS 7.5 HIGH
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.
EPSS 1.55% · 73.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
1.55%
73.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | mbedtls | 2.2.1-2ubuntu0.1, 2.2.1-2ubuntu0.2, 2.2.1-2ubuntu0.3 |
| Ubuntu:20.04:LTS | mbedtls | 0, 2.16.2-1, 2.16.3-1 |
| Ubuntu:18.04:LTS | mbedtls | 0, 2.6.0-1, 2.5.1-1ubuntu1 |
Timeline
- Aug 23, 2021 CVE Published
- Aug 23, 2021 EPSS Score
- Oct 21, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 15, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jun 12, 2022 EPSS Score
- Aug 10, 2022 EPSS Score
- Oct 8, 2022 EPSS Score
- Dec 5, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-36476 third-party-advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.8 third-party-advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.24.0 third-party-advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.7.17 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-36476 third-party-advisory