Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
arm mbed tls vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2021-43666
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and previous versions in the mbedtls_pkcs12_derivation function when an input password's length is 0.
Arm Mbed Tls
Debian Debian Linux 10.0
7.5
CVSSv3
CVE-2021-45450
In Mbed TLS prior to 2.28.0 and 3.x prior to 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Arm Mbed Tls 3.0.0
Arm Mbed Tls
Fedoraproject Fedora 36
Fedoraproject Fedora 37
7.5
CVSSv3
CVE-2021-45451
In Mbed TLS prior to 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Arm Mbed Tls
Fedoraproject Fedora 36
Fedoraproject Fedora 37
9.8
CVSSv3
CVE-2021-44732
Mbed TLS prior to 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
Arm Mbed Tls
Arm Mbed Tls 3.0.0
Debian Debian Linux 10.0
5.9
CVSSv3
CVE-2020-36477
An issue exists in Mbed TLS prior to 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name i...
Arm Mbed Tls
7.5
CVSSv3
CVE-2020-36475
An issue exists in Mbed TLS prior to 2.25.0 (and prior to 2.16.9 LTS and prior to 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.
Arm Mbed Tls
Siemens Logo\\! Cmr2020 Firmware
Siemens Logo\\! Cmr2040 Firmware
Siemens Simatic Rtu3031c Firmware
Siemens Simatic Rtu3041c Firmware
Siemens Simatic Rtu3030c Firmware
Siemens Simatic Rtu3000c Firmware
Debian Debian Linux 9.0
Debian Debian Linux 10.0
7.5
CVSSv3
CVE-2020-36476
An issue exists in Mbed TLS prior to 2.24.0 (and prior to 2.16.8 LTS and prior to 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.
Arm Mbed Tls
Debian Debian Linux 9.0
Debian Debian Linux 10.0
7.5
CVSSv3
CVE-2020-36478
An issue exists in Mbed TLS prior to 2.25.0 (and prior to 2.16.9 LTS and prior to 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then ...
Arm Mbed Tls
Siemens Logo\\! Cmr2020 Firmware
Siemens Logo\\! Cmr2040 Firmware
Siemens Simatic Rtu3031c Firmware
Siemens Simatic Rtu3041c Firmware
Siemens Simatic Rtu3030c Firmware
Siemens Simatic Rtu3000c Firmware
Debian Debian Linux 9.0
Debian Debian Linux 10.0
5.3
CVSSv3
CVE-2020-36421
An issue exists in Arm Mbed TLS prior to 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
Arm Mbed Tls
Debian Debian Linux 10.0
4.7
CVSSv3
CVE-2020-36424
An issue exists in Arm Mbed TLS prior to 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.
Arm Mbed Tls
Debian Debian Linux 10.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site scripting
CVE-2024-5158
XML external entity
CVE-2024-4262
CVE-2024-2036
CVE-2024-4985
CVE-2024-21791
remote attackers
CVE-2023-43208
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »