5
CVSSv2

CVE-2021-45450

Published: 21/12/2021 Updated: 21/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Mbed TLS prior to 2.28.0 and 3.x prior to 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arm mbed tls 3.0.0

arm mbed tls

fedoraproject fedora 36

fedoraproject fedora 37