Search CVE reports


Toggle filters

51 – 60 of 80 results


CVE-2020-16150

Medium priority
Vulnerable

A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-10932

Medium priority
Vulnerable

An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-10941

Medium priority
Needs evaluation

Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2019-18222

Medium priority
Needs evaluation

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2012-2130

Medium priority
Ignored

A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls
polarssl
Show less packages

CVE-2019-16910

Low priority
Needs evaluation

Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-19608

Medium priority
Needs evaluation

Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Needs evaluation
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-0498

Medium priority

Some fixes available 1 of 2

ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Vulnerable
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-0497

Medium priority

Some fixes available 1 of 2

ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of...

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Vulnerable
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-1000520

Low priority
Vulnerable

ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RSA-signed...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages