CVE-2018-19608

MEDIUM

Arm Mbed TLS <2.14.1-2.1.17 - Info Disclosure

Title source: llm
STIX 2.1

Description

Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
http://cat.eyalro.net/

Scores

CVSS v3 4.7
EPSS 0.0024
EPSS Percentile 47.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-269
Status published
Products (1)
arm/mbed_tls 2.1.0 - 2.1.17
Published Dec 05, 2018
Tracked Since Feb 18, 2026