Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-36647

Опубликовано: 17 янв. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.7

Описание

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

2.28.0-1build1
esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

not-affected

2.28.0-1build1
esm-apps/noble

not-affected

2.28.0-1build1
esm-apps/resolute

not-affected

2.28.0-1build1
esm-apps/xenial

ignored

end of ESM support, was needed
focal

ignored

end of standard support, was needs-triage

Показывать по

EPSS

Процентиль: 6%
0.00164
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
больше 3 лет назад

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.

CVSS3: 4.7
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 4.7
debian
больше 3 лет назад

Use of a Broken or Risky Cryptographic Algorithm in the function mbedt ...

CVSS3: 4.7
github
больше 3 лет назад

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.

CVSS3: 4.7
fstec
около 5 лет назад

Уязвимость функции mbedtls_mpi_exp_mod() (lignum.c) программного обеспечения Mbed TLS, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 6%
0.00164
Низкий

4.7 Medium

CVSS3