ID:3038 - Exploit for Man-in-the-Middle (MitM) attack in GnuTLS - CVE-2020-13777
Published: June 19, 2020
GnuTLS
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform Man-in-the-Middle (MitM) attack.
The vulnerability exists due to regression, introduced into the TLS protocol implementation that caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret. A remote attacker can bypass authentication in TLS 1.3 and recover previous conversations in TLS 1.2