Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wwm-8prx-hpg2

Опубликовано: 17 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.

EPSS

Процентиль: 10%
0.00035
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 3 лет назад

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.

CVSS3: 4.7
nvd
около 3 лет назад

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.

CVSS3: 4.7
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 4.7
debian
около 3 лет назад

Use of a Broken or Risky Cryptographic Algorithm in the function mbedt ...

CVSS3: 4.7
fstec
больше 4 лет назад

Уязвимость функции mbedtls_mpi_exp_mod() (lignum.c) программного обеспечения Mbed TLS, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 10%
0.00035
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-327