Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66442

Опубликовано: 01 апр. 2026
Источник: nvd
CVSS3: 5.1
EPSS Низкий

Описание

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
Версия до 4.0.0 (включая)
cpe:2.3:a:arm:tf-psa-crypto:*:*:*:*:*:*:*:*
Версия до 1.0.0 (включая)

EPSS

Процентиль: 4%
0.00016
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-385

Связанные уязвимости

CVSS3: 5.1
ubuntu
3 дня назад

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

CVSS3: 5.9
redhat
5 дней назад

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

CVSS3: 5.1
debian
4 дня назад

In Mbed TLS through 4.0.0, there is a compiler-induced timing side cha ...

CVSS3: 5.1
github
4 дня назад

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

EPSS

Процентиль: 4%
0.00016
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-385