LiveActive security incident?Get immediate response
CVE Record

CVE-2020-36363: Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_...

Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

This CVE flags an AWS CloudFront TLS security policy that permits two CBC-mode cipher suites some organizations classify as weak. The source bundle does not show a software flaw, CVSS score, exploit, or AWS patch. Treat it primarily as a cryptographic configuration and compliance exposure.

Executive priority

Handle through normal security hygiene unless compliance deadlines or customer commitments prohibit CBC cipher suites. No source in the bundle indicates emergency patching or active exploitation.

Technical view

CVE-2020-36363 describes CloudFront TLSv1.2_2019 allowing TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384. No CWE, CVSS vector, affected CPEs, exploitation evidence, or remediation details are provided in the bundle. KEV status is false.

Likely exposure

Exposure is likely limited to CloudFront distributions configured with the TLSv1.2_2019 security policy where internal policy, customer requirements, or scanners disallow those CBC cipher suites.

Exploitation context

The supplied sources do not support active exploitation. This appears to be a standards and cipher-hardening concern, not evidence of a practical compromise path against CloudFront customers.

Researcher notes

Evidence is thin: the CVE record reports weak-cipher acceptance but provides no severity, CWE, affected CPE, exploit status, or fix. Validation should focus on configuration inventory and TLS negotiation results, not exploit reproduction.

Mitigation direction

  • Inventory CloudFront distributions using TLSv1.2_2019.
  • Review AWS guidance for supported CloudFront TLS security policies.
  • If required, move to a policy excluding prohibited CBC cipher suites.
  • Align cipher settings with contractual and regulatory cryptography requirements.
  • Document any accepted exception with business owner approval.

Validation and detection

  • Confirm each distribution's configured viewer TLS security policy.
  • Run an approved TLS scanner against CloudFront hostnames.
  • Verify whether listed CBC cipher suites are accepted.
  • Compare results against organizational cryptography standards.
  • Track AWS and CVE updates for any remediation guidance changes.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-36363 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.