Local Timing Attack Vulnerability in Mbed TLS by ARM
CVE-2025-54764
6.2MEDIUM
What is CVE-2025-54764?
A vulnerability in Mbed TLS prior to version 3.6.5 exposes certain RSA operations to local timing attacks, allowing attackers to potentially gain sensitive information through timing analysis. The affected functions, mbedtls_mpi_mod_inv and mbedtls_mpi_gcd, can be exploited if not properly mitigated, thus compromising the security of cryptographic operations.