CVE-2020-10059
Estado: ModificadaMedia (4.8)—
The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
- Puntuación base: 4.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.21%
- Percentil entre todas las CVEs puntuadas: 68
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-295
- CWE-295
Referencias
- https://docs.zephyrproject.org/latest/security/vulnerabilities.html#cve-2020-10059
- https://github.com/zephyrproject-rtos/zephyr/pull/24954
- https://github.com/zephyrproject-rtos/zephyr/pull/24997
- https://github.com/zephyrproject-rtos/zephyr/pull/24999
- https://zephyrprojectsec.atlassian.net/browse/ZEPSEC-36
- https://docs.zephyrproject.org/latest/security/vulnerabilities.html#cve-2020-10059
- https://github.com/zephyrproject-rtos/zephyr/pull/24954
- https://github.com/zephyrproject-rtos/zephyr/pull/24997
- https://github.com/zephyrproject-rtos/zephyr/pull/24999
- https://zephyrprojectsec.atlassian.net/browse/ZEPSEC-36
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-10059",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "vulnerabilities@zephyrproject.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "vulnerabilities@zephyrproject.org",
"affectedData": [
{
"vendor": "zephyrproject-rtos",
"product": "zephyr",
"versions": [
{
"status": "affected",
"version": "2.1.0",
"lessThan": "unspecified",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-05-11T23:15:11.973",
"references": [
{
"url": "https://docs.zephyrproject.org/latest/security/vulnerabilities.html#cve-2020-10059",
"source": "vulnerabilities@zephyrproject.org"
},
{
"url": "https://github.com/zephyrproject-rtos/zephyr/pull/24954",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "vulnerabilities@zephyrproject.org"
},
{
"url": "https://github.com/zephyrproject-rtos/zephyr/pull/24997",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "vulnerabilities@zephyrproject.org"
},
{
"url": "https://github.com/zephyrproject-rtos/zephyr/pull/24999",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "vulnerabilities@zephyrproject.org"
},
{
"url": "https://zephyrprojectsec.atlassian.net/browse/ZEPSEC-36",
"tags": [
"Third Party Advisory"
],
"source": "vulnerabilities@zephyrproject.org"
},
{
"url": "https://docs.zephyrproject.org/latest/security/vulnerabilities.html#cve-2020-10059",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/zephyrproject-rtos/zephyr/pull/24954",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/zephyrproject-rtos/zephyr/pull/24997",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/zephyrproject-rtos/zephyr/pull/24999",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://zephyrprojectsec.atlassian.net/browse/ZEPSEC-36",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "vulnerabilities@zephyrproject.org",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions."
},
{
"lang": "es",
"value": "El módulo UpdateHub deshabilita la comprobación del peer DTLS, lo que permite un ataque de tipo man in the middle. Esto es mitigado por imágenes de firmware que requieren firmas validas. Sin embargo, no existe ningún beneficio al usar DTLS sin la comprobación del peer. Consulte NCC-ZEP-018. Este problema afecta a: zephyrproject-rtos zephyr versión 2.1.0 y versiones posteriores."
}
],
"lastModified": "2026-06-17T02:47:16.430",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zephyrproject:zephyr:2.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF33DD80-0286-477C-88A4-FCEC0D80F520"
},
{
"criteria": "cpe:2.3:o:zephyrproject:zephyr:2.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "677DD0A3-502D-45F1-9CC8-8DDB8F230DFC"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vulnerabilities@zephyrproject.org"
}