PT-2020-11889 · Zephyr · Zephyr

David Brown

·

Published

2020-05-11

·

Updated

2020-06-05

·

CVE-2020-10059

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions zephyr version 2.1.0 and later versions
Description The issue concerns the UpdateHub module, which disables DTLS peer checking. This allows for a man-in-the-middle attack. However, firmware images require valid signatures, mitigating the issue to some extent. It's noted that there's no benefit to using DTLS without peer checking.
Recommendations For zephyr version 2.1.0 and later versions, consider disabling the UpdateHub module until a patch is available that enables DTLS peer checking. As a mitigation measure, ensure that all firmware images are properly signed to minimize the risk of exploitation.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10059

Affected Products

Zephyr