Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-23170

Опубликовано: 28 нояб. 2024
Источник: msrc
CVSS3: 5.5
EPSS Низкий

Описание

Описание отсутствует

EPSS

Процентиль: 39%
0.00175
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

CVSS3: 5.5
nvd
около 2 лет назад

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

CVSS3: 5.5
debian
около 2 лет назад

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3 ...

suse-cvrf
около 2 лет назад

Security update for mbedtls

CVSS3: 5.5
github
около 2 лет назад

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

EPSS

Процентиль: 39%
0.00175
Низкий

5.5 Medium

CVSS3