Vulnerability in Arm Mbed TLS Affects RSA and Diffie-Hellman Key Generation
CVE-2020-36424
4.7MEDIUM
Summary
An issue has been identified in Arm Mbed TLS, which includes a vulnerability that can be exploited through side-channel attacks during the generation of base blinding/unblinding values. This allows an attacker to recover private keys associated with RSA or static Diffie-Hellman protocols. It is important for users of Mbed TLS versions prior to 2.24.0 to implement necessary updates to mitigate this security risk. The vulnerability highlights the importance of robust cryptographic implementations to prevent potential exploitation.
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved