PT-2020-11889 · Zephyr · Zephyr
David Brown
·
Published
2020-05-11
·
Updated
2020-06-05
·
CVE-2020-10059
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
zephyr version 2.1.0 and later versions
Description
The issue concerns the UpdateHub module, which disables DTLS peer checking. This allows for a man-in-the-middle attack. However, firmware images require valid signatures, mitigating the issue to some extent. It's noted that there's no benefit to using DTLS without peer checking.
Recommendations
For zephyr version 2.1.0 and later versions, consider disabling the UpdateHub module until a patch is available that enables DTLS peer checking. As a mitigation measure, ensure that all firmware images are properly signed to minimize the risk of exploitation.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zephyr