Arm · Arm Mbed Tls · CVE-2020-36425
**Name of the Vulnerable Software and Affected Versions**
Arm Mbed TLS versions prior to 2.24.0
**Description**
The issue is related to the incorrect use of a revocationDate check when deciding whether to honor certificate revocation via a CRL. This can be exploited by an attacker in certain situations by changing the local clock, potentially affecting data integrity.
**Recommendations**
For Arm Mbed TLS versions prior to 2.24.0, update to version 2.24.0 or later to resolve the issue. As a temporary workaround, consider restricting access to certificate revocation lists (CRLs) to minimize the risk of exploitation.