In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 14, 2021 |
| Debian | — | Upgrade mbedtls | Nov 29, 2021 | Jul 14, 2021 |
| Suse | — | Upgrade libmbedcrypto3Upgrade libmbedtls12-32bitUpgrade mbedtls-develUpgrade libmbedtls12-64bitUpgrade libmbedx509-0Upgrade libmbedx509-0-32bitUpgrade libmbedx509-0-64bitUpgrade libmbedcrypto3-32bitUpgrade libmbedcrypto3-64bitUpgrade libmbedtls12 | Oct 12, 2021 | Jul 14, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub