Observable Timing Discrepancy in Mbed TLS Product by ARM
CVE-2025-59438

5.3MEDIUM

Key Information:

Vendor

ARM

Status
Vendor
CVE Published:
21 October 2025

What is CVE-2025-59438?

Mbed TLS versions up to 3.6.4 are affected by an observable timing discrepancy that could potentially allow attackers to exploit the differences in processing time. This vulnerability poses a threat to the underlying security mechanisms, making it essential to address it promptly. Users are advised to review their implementations and consider upgrading to the latest version to mitigate the risk associated with this timing issue.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.