An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mbedtls2Upgrade mbedtlsUpgrade mbedtls3 | Mar 26, 2024 | Jan 31, 2024 |
| Debian | — | Upgrade mbedtlsNo solution exists | May 15, 2025 | Jan 31, 2024 |
| Gentoo Linux | — | Upgrade net-libs/mbedtls. | Sep 23, 2024 | Jan 31, 2024 |
| Suse | — | Upgrade libmbedx509-1-64bitUpgrade libmbedcrypto7-32bitUpgrade libmbedx509-1Upgrade libmbedcrypto7Upgrade libmbedtls14Upgrade libmbedcrypto7-64bitUpgrade mbedtls-develUpgrade libmbedtls14-64bitUpgrade libmbedtls14-32bitUpgrade libmbedx509-1-32bit | Feb 1, 2024 | Feb 1, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub