PT-2024-1658 · Mbed Tls+3 · Mbed Tls+3
Hubert Kario
·
Published
2024-01-10
·
Updated
2026-05-05
·
CVE-2024-23170
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mbed TLS versions 2.x before 2.28.7
Mbed TLS versions 3.x before 3.5.2
Description
A timing side channel in RSA private operations could allow a local attacker to recover the plaintext by sending a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario. This side channel could be exploited by a remote attacker to gain access to confidential information.
Recommendations
For Mbed TLS versions 2.x before 2.28.7, update to version 2.28.7 or later to resolve the issue.
For Mbed TLS versions 3.x before 3.5.2, update to version 3.5.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to RSA private operations until a patch is available.
Fix
Information Disclosure
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Mbed Tls