cbcvebase.

Trustedfirmware Mbed Tls vulnerabilities

41 known vulnerabilities affecting trustedfirmware/mbed_tls.

Total CVEs
41
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH13MEDIUM16LOW1

Vulnerabilities

Page 2 of 3
CVE-2015-5291P3MEDIUMCVSS 6.8≥ 1.3.0, < 1.3.14≥ 2.0.0, < 2.1.22015-11-02
CVE-2015-5291 [MEDIUM] CWE-119 CVE-2015-5291: Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is not properly handled when creating a
nvd
CVE-2018-9989P4HIGHCVSS 7.5v2.8.0-rc12018-04-10
CVE-2018-9989 [HIGH] CWE-125 CVE-2018-9989: ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_serve ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.
nvd
CVE-2024-23744P4HIGHCVSS 7.5≤ 3.5.12024-01-21
CVE-2024-23744 [HIGH] CWE-400 CVE-2024-23744: An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.
nvd
CVE-2025-49601P3MEDIUMCVSS 6.5≥ 3.3.0, < 3.6.42025-07-04
CVE-2025-49601 [MEDIUM] CWE-125 CVE-2025-49601: In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncated input. Specifically, an out-of-bounds read in mbedtls_lms_import_public_key allows context-dependent attackers to trigger a crash or limited adjacent-
nvd
CVE-2018-9988P4HIGHCVSS 7.5v2.8.0-rc12018-04-10
CVE-2018-9988 [HIGH] CWE-125 CVE-2018-9988: ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_serve ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
nvd
CVE-2024-23775P4HIGHCVSS 7.5≥ 3.0.0, < 3.5.22024-01-31
CVE-2024-23775 [HIGH] CWE-190 CVE-2024-23775: Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
nvd
CVE-2024-28755P4MEDIUMCVSS 6.5≥ 3.5.0, ≤ 3.6.02024-04-03
CVE-2024-28755 [MEDIUM] CWE-326 CVE-2024-28755: An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedt An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker was able to prevent an Mbed TLS server from establishing any TLS 1.3 connection, potentially resulting in a Denial of Service or f
nvd
CVE-2015-8036P4MEDIUMCVSS 6.8≥ 1.3.0, < 1.3.14≥ 2.0.0, < 2.1.22015-11-02
CVE-2015-8036 [MEDIUM] CVE-2015-8036: Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2. Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the session ticket extension, which is not properly handled when creating a ClientHello message to resume a session.
nvd
CVE-2026-25834P4MEDIUMCVSS 6.5≥ 3.3.0, < 3.6.6v4.0.02026-04-01
CVE-2026-25834 [MEDIUM] CWE-295 CVE-2026-25834: Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade. Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
nvd
CVE-2024-28836P4MEDIUMCVSS 5.4≥ 3.5.0, < 3.6.02024-04-03
CVE-2024-28836 [MEDIUM] CWE-835 CVE-2024-28836: An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the serv An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall back to the TLS 1.2 implementation of the protocol if it is disabled. If the TLS 1.2 implementation was disabled at build time, a TLS 1.2 client could put a TLS 1.3-only server into an infinite loop processing a TLS 1.2 ClientHell
nvd
CVE-2019-16910P4MEDIUMCVSS 5.3≥ 2.17.0, < 2.19.02019-09-26
CVE-2019-16910 [MEDIUM] CVE-2019-16910: Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, us Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)
nvd
CVE-2025-27809P4MEDIUMCVSS 5.4≥ 3.0.0, < 3.6.32025-03-25
CVE-2025-27809 [MEDIUM] CWE-1188 CVE-2025-27809: Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
nvd
CVE-2022-46392P4MEDIUMCVSS 5.3≥ 3.0.0, < 3.3.02022-12-15
CVE-2022-46392 [MEDIUM] CWE-203 CVE-2022-46392: An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_
nvd
CVE-2024-23170P4MEDIUMCVSS 5.5≥ 3.0.0, < 3.5.22024-01-31
CVE-2024-23170 [MEDIUM] CWE-203 CVE-2024-23170: An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" b
nvd
CVE-2025-27810P4MEDIUMCVSS 4.8≥ 3.0.0, < 3.6.32025-03-25
CVE-2025-27810 [MEDIUM] CWE-908 CVE-2025-27810: Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
nvd
CVE-2024-45157P4MEDIUMCVSS 5.1≥ 2.26.0, < 2.28.9≥ 3.2.0, < 3.6.12024-09-05
CVE-2024-45157 [MEDIUM] CWE-696 CVE-2024-45157: An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected a An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.
nvd
CVE-2020-10932P4MEDIUMCVSS 4.7≥ 2.16.0, < 2.16.62020-04-15
CVE-2020-10932 [MEDIUM] CWE-203 CVE-2020-10932: An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective coordinate of the result of scalar multiplication by exploiting side channels in the conversion to affine coordinates; (2) usi
nvd
CVE-2021-36647P4MEDIUMCVSS 4.7≥ 2.28.0, < 3.0.02023-01-17
CVE-2021-36647 [MEDIUM] CWE-327 CVE-2021-36647: Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c i Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secur
nvd
CVE-2025-49600P4MEDIUMCVSS 4.9≥ 3.3.0, < 3.6.42025-07-04
CVE-2025-49600 [MEDIUM] CWE-325 CVE-2025-49600: In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifically, unchecked return values in mbedtls_lms_verify allow an attacker (who can induce a hardware hash accelerator fault) to bypass LMS
nvd
CVE-2018-19608P4MEDIUMCVSS 4.7≥ 2.14.0, < 2.14.12018-12-05
CVE-2018-19608 [MEDIUM] CWE-269 CVE-2018-19608: Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
nvd
Trustedfirmware Mbed Tls vulnerabilities | cvebase