PT-2021-24239 · Mbed Tls+1 · Mbed Tls+1

Published

2021-12-18

·

Updated

2022-12-08

·

CVE-2021-45451

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mbed TLS versions prior to 3.1.0
Description: The issue allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application, specifically through the psa aead generate nonce function.
Recommendations: For versions prior to 3.1.0, update to version 3.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to memory locations that could be accessed by untrusted applications to minimize the risk of exploitation.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3553
ALT-PU-2022-2561
CVE-2021-45451

Affected Products

Alt Linux
Mbed Tls