High severity7.5NVD Advisory· Published Aug 23, 2021· Updated Jun 17, 2026
CVE-2020-36478
CVE-2020-36478
Description
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:o:siemens:logo\!_cmr2020_firmware:*:*:*:*:*:*:*:*Range: <2.2
- cpe:2.3:o:siemens:logo\!_cmr2040_firmware:*:*:*:*:*:*:*:*Range: <2.2
- cpe:2.3:o:siemens:simatic_rtu3000c_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:siemens:simatic_rtu3030c_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:siemens:simatic_rtu3031c_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:siemens:simatic_rtu3041c_firmware:*:*:*:*:*:*:*:*
- Mbed TLS/Mbed TLSdescription
Patches
Vulnerability mechanics
References
7- cert-portal.siemens.com/productcert/pdf/ssa-756638.pdfnvdPatchThird Party Advisory
- github.com/ARMmbed/mbedtls/issues/3629nvdExploitThird Party Advisory
- github.com/ARMmbed/mbedtls/releases/tag/v2.16.9nvdRelease NotesThird Party Advisory
- github.com/ARMmbed/mbedtls/releases/tag/v2.25.0nvdRelease NotesThird Party Advisory
- github.com/ARMmbed/mbedtls/releases/tag/v2.7.18nvdRelease NotesThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/11/msg00021.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/12/msg00036.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.