ID:3472 - Exploit for Man-in-the-Middle (MitM) attack in GnuTLS - CVE-2020-13777

 
Main Vulnerability Database Exploits ID:3472 - Exploit for Man-in-the-Middle (MitM) attack in GnuTLS - CVE-2020-13777

ID:3472 - Exploit for Man-in-the-Middle (MitM) attack in GnuTLS - CVE-2020-13777

Published: July 15, 2020


Vulnerability identifier: #VU28557
Vulnerability risk: Medium
CVE-ID: CVE-2020-13777
CWE-ID: CWE-300
Exploitation vector: Adjecent network
Vulnerable software:
GnuTLS

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform Man-in-the-Middle (MitM) attack.

The vulnerability exists due to regression, introduced into the TLS protocol implementation that caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret. A remote attacker can bypass authentication in TLS 1.3 and recover previous conversations in TLS 1.2


Remediation

Install updates from vendor's website.