PT-2021-6717 · Arm+2 · Mbed Tls+2
Hyesoon Kim
+6
·
Published
2020-07-02
·
Updated
2023-01-11
·
CVE-2020-36423
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Arm Mbed TLS versions prior to 2.23.0
Description
A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator. This issue is related to the implementation of TLS and SSL protocols in Mbed TLS, allowing an attacker to access confidential data.
Recommendations
For versions prior to 2.23.0, update to version 2.23.0 or later to resolve the issue. As a temporary workaround, consider disabling hardware acceleration for TLS and SSL protocols until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Mbed Tls