CVE-2024-45157
published 2024-09-05CVE-2024-45157: An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented…
PriorityP422medium5.1CVSS 3.1
AVLACHPRNUINSUCHINAN
EPSS
0.24%
15.0th percentile
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mbedtls | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| trustedfirmware | mbed_tls | >= 2.26.0 < 2.28.9 | 2.28.9 |
| trustedfirmware | mbed_tls | >= 3.2.0 < 3.6.1 | 3.6.1 |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.1MEDIUM
vendor_debian5.1LOW
vendor_msrc5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2024-45157: NIST NVD Details: https://nvd
vendor_msrc·2024-11-12·CVSS 5.1
CVE-2024-45157 [MEDIUM] CVE-2024-45157: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2024-45157
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Remediation: hvloader
Reference: https://nvd.nist.gov/vuln/detail/CVE-2024-45157
Debian
CVE-2024-45157: mbedtls - An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which...
vendor_debian·2024·CVSS 5.1
CVE-2024-45157 [MEDIUM] CVE-2024-45157: mbedtls - An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which...
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.
Scope: local
bookworm: open
bullseye: resolved
forky: open
sid: open
trixie: open
OSV
CVE-2024-45157: An issue was discovered in Mbed TLS before 2
osv·2024-09-05·CVSS 5.1
CVE-2024-45157 [MEDIUM] CVE-2024-45157: An issue was discovered in Mbed TLS before 2
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.
GHSA
GHSA-cvp8-hm87-hr8x: An issue was discovered in Mbed TLS before 2
ghsa_unreviewed·2024-09-05
CVE-2024-45157 [MEDIUM] CWE-696 GHSA-cvp8-hm87-hr8x: An issue was discovered in Mbed TLS before 2
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.
No detection rules found.
No public exploits indexed.
2024-09-05
Published