Improper Certificate Validation in zephyr - CVE-2020-10059

 

Improper Certificate Validation in zephyr - CVE-2020-10059

Published: May 12, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34396
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-10059
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: rutantan
Affected software:
zephyr

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions.


How to mitigate CVE-2020-10059

Install update from vendor's website.

Sources