ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mbedtls2Upgrade mbedtlsUpgrade mbedtls3 | Aug 15, 2018 | Jul 28, 2018 |
| Debian | — | Upgrade mbedtls | Sep 18, 2018 | Jul 28, 2018 |
| Freebsd | — | Upgrade mbedtls | Aug 11, 2018 | Aug 10, 2018 |
| Ubuntu | — | Upgrade libmbedx509-0Upgrade libmbedtls10Upgrade libmbedcrypto0 | Feb 6, 2020 | Jul 28, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub