ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3967-1 | mbedtls security update |
EUVD |
EUVD-2017-5547 | ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 05 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trustedfirmware
Trustedfirmware mbed Tls |
|
| CPEs | cpe:2.3:a:arm:mbed_tls:1.3.11:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:1.3.12:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:1.3.13:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:1.3.14:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:1.3.15:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:1.3.16:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:1.3.17:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:1.3.18:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:1.3.20:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.0.0:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.1.0:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.1.1:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.1.2:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.1.3:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.1.4:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.1.5:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.1.6:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.1.8:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.2.0:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.2.1:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.3.0:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.4.0:*:*:*:*:*:*:* cpe:2.3:a:arm:mbed_tls:2.5.1:*:*:*:*:*:*:* |
cpe:2.3:a:trustedfirmware:mbed_tls:1.3.10:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:1.3.11:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:1.3.12:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:1.3.13:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:1.3.14:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:1.3.15:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:1.3.16:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:1.3.17:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:1.3.18:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:1.3.20:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.0.0:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.1.0:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.1.1:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.1.2:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.1.3:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.1.4:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.1.5:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.1.6:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.1.8:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.2.0:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.2.1:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.3.0:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.4.0:*:*:*:*:*:*:* cpe:2.3:a:trustedfirmware:mbed_tls:2.5.1:*:*:*:*:*:*:* |
| Vendors & Products |
Trustedfirmware
Trustedfirmware mbed Tls |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:13:41.938Z
Reserved: 2017-08-30T00:00:00.000Z
Link: CVE-2017-14032
No data.
Status : Modified
Published: 2017-08-30T20:29:00.337
Modified: 2026-06-05T19:38:32.047
Link: CVE-2017-14032
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD