CVE-2017-14032

Source
https://cve.org/CVERecord?id=CVE-2017-14032
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14032.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-14032
Downstream
Related
Published
2017-08-30T20:29:00.337Z
Modified
2026-03-10T14:21:50.439738Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

References

Affected packages

Git / github.com/armmbed/mbedtls

Affected ranges

Type
GIT
Repo
https://github.com/armmbed/mbedtls
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.10"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.11"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.12"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.13"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.14"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.15"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.16"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.17"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.18"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.19"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.20"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.21"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.7"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.8"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.9"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.5.1"
        }
    ]
}
Type
Repo
https://github.com/mbed-tls/mbedtls
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
31458a18788b0cf0b722acda9bb2f2fe13a3fb32
Fixed
d15795acd5074e0b44e71f7ede8bdfe1b48591fc

Affected versions

mbedtls-1.*
mbedtls-1.3.10
polarssl-1.*
polarssl-1.2.0
polarssl-1.2.1
polarssl-1.2.2
polarssl-1.2.3
polarssl-1.2.4
polarssl-1.2.5
polarssl-1.2.6
polarssl-1.3.0
polarssl-1.3.0-rc0
polarssl-1.3.1
polarssl-1.3.2
polarssl-1.3.3
polarssl-1.3.4
polarssl-1.3.5
polarssl-1.3.6
polarssl-1.3.7
polarssl-1.3.8
polarssl-1.3.9

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2.6.2"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14032.json"