Search CVE reports


Toggle filters

41 – 50 of 74 results


CVE-2020-36423

Medium priority
Vulnerable

An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-36422

Medium priority
Vulnerable

An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-36421

Medium priority
Vulnerable

An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2021-24119

Low priority
Needs evaluation

In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and...

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Needs evaluation Needs evaluation Needs evaluation Needs evaluation
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-16150

Medium priority
Vulnerable

A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-10932

Medium priority
Vulnerable

An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-10941

Medium priority
Needs evaluation

Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2019-18222

Medium priority
Needs evaluation

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2012-2130

Medium priority
Ignored

A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls
polarssl
Show less packages

CVE-2019-16910

Low priority
Needs evaluation

Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Needs evaluation
Show less packages