SB2020090941 - Insufficient verification of data authenticity in The Update Framework (TUF)



SB2020090941 - Insufficient verification of data authenticity in The Update Framework (TUF)

Published: September 9, 2020 Updated: May 18, 2026

Security Bulletin ID SB2020090941
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Insufficient verification of data authenticity (CVE-ID: CVE-2020-15163)

CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to control the trust chain for future updates.

The vulnerability exists due to improper verification of root metadata in the root metadata update workflow when processing multiple new versions of root metadata. A remote attacker can serve crafted root metadata through a man-in-the-middle position to control the trust chain for future updates.

The issue occurs because a previously downloaded root metadata file that failed verification at download time may later become trusted.


Remediation

Install update from vendor's website.