Improper Authentication in otp - CVE-2020-35733

 

Improper Authentication in otp - CVE-2020-35733

Published: April 10, 2026


Vulnerability identifier: #VU125769
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-35733
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper authentication in the ssl component when validating a certificate chain that includes a trusted root certificate. A remote attacker can present a fake certificate chain to disclose sensitive information.

The issue only occurs under conditions when the root certificate is sent in the chain.


Affected software

otp
Arch Linux
Fedora
erlang

How to mitigate CVE-2020-35733

Install security update from vendor's website.

otp - update to 23.2.2
erlang - update to 23.2.2-1
erlang - update to 23.2.3-1.fc33

External References

Related Security Bulletins