Manuel Pégourié-Gonnard

2 exploits Active since Aug 2017
CVE-2017-14032 WRITEUP HIGH WRITEUP
ARM mbed TLS <2.1.9 - Auth Bypass
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.
CVSS 8.1
CVE-2019-16910 WRITEUP MEDIUM WRITEUP
Arm Mbed TLS <2.19.0 & Arm Mbed Crypto <2.0.0 - Info Disclosure
Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)
CVSS 5.3