PT-2020-6619 · Mbed Tls+1 · Mbed Tls+1

Kfyatek

·

Published

2020-07-17

·

Updated

2025-08-21

·

CVE-2020-36477

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mbed TLS versions prior to 2.24.0
Description An issue in the verification of X.509 certificates allows an attacker to impersonate a domain by getting a certificate for the corresponding IPv4 or IPv6 address, provided they control that IP address. The problem arises when the subjectAltName extension is present, and the expected name is compared to any name in that extension regardless of its type.
Recommendations For versions prior to 2.24.0, update to version 2.24.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the mbedtls x509 crt verify function until a patch is available. Avoid using the cn argument of mbedtls x509 crt verify with certificates that have a subjectAltName extension until the issue is resolved.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2711
ALT-PU-2021-2234
ALT-PU-2025-10462
BDU:2022-01651
CVE-2020-36477

Affected Products

Alt Linux
Mbed Tls