CVE-2018-0497ARM Mbed TLS vulnerability

8 documents7 sources
Severity
5.9MEDIUMNVD
CNA2.6OSV9.8OSV2.6
EPSS
0.3%
top 44.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 28
Latest updateMay 13

Description

ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (with a wrong SHA-384 calculation) for CVE-2013-0169.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

NVDarm/mbed_tls2.2.02.7.5+2
Debianmbed/mbedtls< 2.12.0-1+3
Ubuntumbed/mbedtls< 2.2.1-2ubuntu0.3

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

4
GHSA
GHSA-pxhv-jv3r-8j7f: ARM mbed TLS before 22022-05-13
OSV
mbedtls vulnerabilities2020-02-05
OSV
CVE-2018-0497: ARM mbed TLS before 22018-07-28
CVEList
CVE-2018-0497: ARM mbed TLS before 22018-07-28

📋Vendor Advisories

2
Ubuntu
ARM mbed TLS vulnerabilities2020-02-05
Debian
CVE-2018-0497: mbedtls - ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attack...2018

💬Community

1
Bugzilla
CVE-2018-0498 CVE-2018-0497 mbedtls: Two critical flaws fixed in latest release2018-08-02
CVE-2018-0497 — ARM Mbed TLS vulnerability | cvebase