PT-2021-6813 · Arm+4 · Mbed Tls+4

Hubert Kario

·

Published

2021-03-13

·

Updated

2025-08-21

·

CVE-2021-24119

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mbed TLS version 2.24.0
Description A side-channel vulnerability in base64 PEM file decoding exists, allowing system-level attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments. This issue is related to the use of base64 decoding functionality with non-constant execution time, which can be exploited by a remote attacker to access confidential data.
Recommendations For Mbed TLS version 2.24.0, consider disabling the base64 PEM file decoding functionality as a temporary workaround until a patch is available. Restrict access to sensitive data and confidential information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1478
ALT-PU-2021-2234
ALT-PU-2025-10462
BDU:2022-02236
CVE-2021-24119
DLA-2826-1
DLA-3249-1
DLA-4236-1
OPENSUSE-SU-2021:1344-1
OPENSUSE-SU-2021:1355-1
OPENSUSE-SU-2021:1389-1
OPENSUSE-SU-2021_1344-1
OPENSUSE-SU-2024:11552-1

Affected Products

Alt Linux
Astra Linux
Debian
Mbed Tls
Suse