PT-2021-6717 · Arm+2 · Mbed Tls+2

Hyesoon Kim

+6

·

Published

2020-07-02

·

Updated

2023-01-11

·

CVE-2020-36423

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Arm Mbed TLS versions prior to 2.23.0
Description A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator. This issue is related to the implementation of TLS and SSL protocols in Mbed TLS, allowing an attacker to access confidential data.
Recommendations For versions prior to 2.23.0, update to version 2.23.0 or later to resolve the issue. As a temporary workaround, consider disabling hardware acceleration for TLS and SSL protocols until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2262
ALT-PU-2020-2355
BDU:2022-02080
CVE-2020-36423
DLA-3249-1

Affected Products

Alt Linux
Astra Linux
Mbed Tls