Weakness in Modular Exponentiation Affects Arm Mbed TLS
CVE-2020-36421
5.3MEDIUM
What is CVE-2020-36421?
A side channel vulnerability was identified in Arm Mbed TLS prior to version 2.23.0, which can lead to the exposure of an RSA private key utilized within a secure enclave. The issue stems from how modular exponentiation is handled during cryptographic operations. If exploited, this vulnerability could allow an attacker to obtain sensitive cryptographic material, thereby compromising the security of applications relying on Mbed TLS for secure communications.