2.1
CVSSv2

CVE-2020-16150

Published: 02/09/2020 Updated: 27/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS up to and including 2.23.0 allows an malicious user to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arm mbed tls

fedoraproject fedora 31

fedoraproject fedora 32

fedoraproject fedora 33

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #972806 mbedtls security advisories: local side channel attacks Package: src:mbedtls; Maintainer for src:mbedtls is James Cowgill <jcowgill@debianorg>; Reported by: Glenn Strauss <gs-debianorg@gluelogiccom> Date: Sat, 24 Oct 2020 05:27:02 UTC Severity: serious Tags: security, upstream Fou ...
A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msgc in Trusted Firmware Mbed TLS through 2230 allows an attacker to recover secret key information This affects CBC mode because of a computed time difference based on a padding length The issue is fixed in Mbed TLS 2240, 2168 and 2717 ...