CVE-2019-18222
MEDIUMArm Mbed Crypto < 3.0.0 and Mbed TLS < 2.7.13 - ECDSA Private Key Recovery via Side-Channel Attack
Title source: llmDescription
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.
References (5)
Core 5
Core References
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NGDACU65MYZXXVPQP2EBHUJGOR4RWLVY/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3GWQNONS7GRORXZJ7MOJFUEJ2ZJ4OUW/
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/12/msg00036.html
Vendor Advisory
https://tls.mbed.org/tech-updates/security-advisories
Scores
CVSS v3
4.7
EPSS
0.0013
EPSS Percentile
31.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-203
Status
published
Products (5)
arm/mbed_crypto
< 3.0.0
arm/mbed_tls
< 2.7.13
debian/debian_linux
10.0
fedoraproject/fedora
30
fedoraproject/fedora
31
Published
Jan 23, 2020
Tracked Since
Feb 18, 2026