V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2020-13777
DEB
HighConfirmedExploit available

GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authen…

CVSS
7.4
High
EPSS
0.01
p79
Published
2020-01-01
Updated
2020-01-01
Description

GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.

Tags · CWE
Pre-authCrypto
CWE-327
CWE-345
CAPEC-20
CAPEC-97
CAPEC-111
CAPEC-141
CAPEC-142
CAPEC-148
CAPEC-218
CAPEC-384
CAPEC-385
CAPEC-386
CAPEC-387
CAPEC-388
CAPEC-459
CAPEC-473
CAPEC-475
CAPEC-608
CAPEC-614
CAPEC-665
CAPEC-701
Affected products
GnutlsGnutlsGnutlsGnutlsGnutls-utilsGnutls28Gnutls28Gnutls28Gnutls28Gnutls28Gnutls28Gnutls28Gnutls28Gnutls30-devel-docLibgnutls-develLibgnutls-guileLibgnutls-openssl-develLibgnutls27-opensslLibgnutls30Libgnutlsxx-devel
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.012 · p79
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-473 · CWE-327
└ via CAPEC-665 · CWE-345
└ via CAPEC-148 · CWE-345
└ via CAPEC-665 · CWE-345
└ via CAPEC-473 · CWE-327
└ via CAPEC-665 · CWE-345
└ via CAPEC-141 · CWE-345
└ via CAPEC-142 · CWE-345
Known exploits — Сканер-ВС
CVE-2020-13777
github-poc · https://github.com/prprhyt/PoC_TLS1_3_CVE-2020-13777
Enterprise
Affected software
ProductVendorStatus
gnutlsTracked
gnutlsTracked
gnutlsTracked
gnutlsTracked
gnutls-utilsTracked
gnutls28Tracked
gnutls28Tracked
gnutls28Tracked
gnutls28Tracked
gnutls28Tracked
gnutls28Tracked
gnutls28Tracked
gnutls28Tracked
gnutls30-devel-docTracked
libgnutls-develTracked
libgnutls-guileTracked
libgnutls-openssl-develTracked
libgnutls27-opensslTracked
libgnutls30Tracked
libgnutlsxx-develTracked
Source databases
DEB
CVE
RED
UBU