CyberSec.Space Logo
Back to CVE Browser

CVE-2017-18187

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0140%
EPSS Percentile9.79th
PublishedFeb 14, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

Affected Platforms (CPE)

πŸ“¦
Arm

Mbed Tls

< 2.7.0
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0

References & Advisories

Related Vulnerabilities