VulnerabilityModified
CVE-2018-19608
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
MEDIUM 4.7EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
- CVSS 3.0
- 4.7 MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- arm/mbed tls · trustedfirmware/mbed tls
- Source
- cve@mitre.org
References
- http://cat.eyalro.net/Third Party Advisory
- https://tls.mbed.org/tech-updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-releasedThird Party Advisory
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2018-03Third Party Advisory
- http://cat.eyalro.net/Third Party Advisory
- https://tls.mbed.org/tech-updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-releasedThird Party Advisory
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2018-03Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.