cbcvebase.

Arm Mbed Tls vulnerabilities

52 known vulnerabilities affecting arm/mbed_tls.

Total CVEs
52
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH19MEDIUM24

Vulnerabilities

Page 3 of 3
CVE-2020-16150P4MEDIUMCVSS 5.5fixed in 2.7.17≥ 2.8.0, < 2.16.8+1 more2020-09-02
CVE-2020-16150 [MEDIUM] CWE-203 CVE-2020-16150: A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware M A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.
nvd
CVE-2024-23170P4MEDIUMCVSS 5.5≥ 2.0.0, < 2.28.72024-01-31
CVE-2024-23170 [MEDIUM] CWE-203 CVE-2024-23170: An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" b
nvd
CVE-2021-24119P4MEDIUMCVSS 4.9fixed in 2.26.02021-07-14
CVE-2021-24119 [MEDIUM] CWE-203 CVE-2021-24119: In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
nvd
CVE-2025-66442P4MEDIUMCVSS 5.1≤ 4.0.02026-04-01
CVE-2025-66442 [MEDIUM] CWE-385 CVE-2025-66442: In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decry In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.
nvd
CVE-2025-27810P4MEDIUMCVSS 4.8fixed in 2.28.102025-03-25
CVE-2025-27810 [MEDIUM] CWE-908 CVE-2025-27810: Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
nvd
CVE-2025-52497P4MEDIUMCVSS 4.8fixed in 3.6.42025-07-04
CVE-2025-52497 [MEDIUM] CWE-193 CVE-2025-52497: Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_bu Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.
nvd
CVE-2020-10932P4MEDIUMCVSS 4.7≥ 2.7.0, < 2.7.152020-04-15
CVE-2020-10932 [MEDIUM] CWE-203 CVE-2020-10932: An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective coordinate of the result of scalar multiplication by exploiting side channels in the conversion to affine coordinates; (2) usi
nvd
CVE-2021-36647P4MEDIUMCVSS 4.7fixed in 2.16.11≥ 2.17.0, < 2.27.02023-01-17
CVE-2021-36647 [MEDIUM] CWE-327 CVE-2021-36647: Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c i Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secur
nvd
CVE-2018-0498P4MEDIUMCVSS 4.7fixed in 2.1.14≥ 2.2.0, < 2.7.5+1 more2018-07-28
CVE-2018-0498 [MEDIUM] CVE-2018-0498: ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial pl ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.
nvd
CVE-2020-36424P4MEDIUMCVSS 4.7fixed in 2.7.17≥ 2.8.0, < 2.16.8+1 more2021-07-19
CVE-2020-36424 [MEDIUM] CWE-203 CVE-2020-36424: An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RS An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.
nvd
CVE-2019-18222P4MEDIUMCVSS 4.7fixed in 2.7.13≥ 2.8.0, < 2.16.4+1 more2020-01-23
CVE-2019-18222 [MEDIUM] CWE-203 CVE-2019-18222: The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 doe The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.
nvd
CVE-2018-19608P4MEDIUMCVSS 4.7≥ 2.1.0, < 2.1.17≥ 2.7.0, < 2.7.82018-12-05
CVE-2018-19608 [MEDIUM] CWE-269 CVE-2018-19608: Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
nvd
Arm Mbed Tls vulnerabilities | cvebase