Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-28960

Опубликовано: 29 мар. 2024
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.

Отчет

This vulnerability affects products that use Mbed TLS to provide an implementation of the PSA Crypto API with domain isolation between API callers (“client application”) and the API implementation (“crypto server”), where communication is done through shared memory. Applications that use Mbed TLS as a library inside their own process space are not affected.

Ссылки на источники

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2272172mbedtls: Insecure handling of shared memory in PSA Crypto APIs

EPSS

Процентиль: 34%
0.00134
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
около 1 года назад

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.

CVSS3: 8.2
nvd
около 1 года назад

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.

CVSS3: 8.2
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 8.2
debian
около 1 года назад

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28. ...

CVSS3: 8.2
github
около 1 года назад

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.

EPSS

Процентиль: 34%
0.00134
Низкий

5.3 Medium

CVSS3