← Back to CVE List

CVE-2018-1000520

Published: 2018-06-26T16:29Z
Last Modified: 2024-11-21T03:40Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RSA-signed ones should be.. This attack appear to be exploitable via Peers negotiate a TLS-ECDH-RSA-* ciphersuite. Any of the peers can then provide an ECDSA-signed certificate, when only an RSA-signed one should be accepted.. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt