4.7
CVSSv3

CVE-2019-18222

Published: 23/01/2020 Updated: 03/03/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS up to and including 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local malicious user to recover the private key via side-channel attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arm mbed tls

arm mbed crypto

fedoraproject fedora 30

fedoraproject fedora 31

debian debian linux 10.0

Vendor Advisories

Severity Unknown Remote Unknown Type Unknown Description AVG-1104 mbedtls 2163-1 Unknown Vulnerable ...