Local Timing Attack Vulnerability in Mbed TLS by ARM
CVE-2025-54764

6.2MEDIUM

Key Information:

Vendor

ARM

Status
Vendor
CVE Published:
20 October 2025

What is CVE-2025-54764?

A vulnerability in Mbed TLS prior to version 3.6.5 exposes certain RSA operations to local timing attacks, allowing attackers to potentially gain sensitive information through timing analysis. The affected functions, mbedtls_mpi_mod_inv and mbedtls_mpi_gcd, can be exploited if not properly mitigated, thus compromising the security of cryptographic operations.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.