Trustedfirmware

Mbed Tls

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 02.04.2026 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:38:32

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, lea...

  • EPSS 0.39%
  • Veröffentlicht 02.04.2026 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:38:32

An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len ...

  • EPSS 0.24%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:38:32

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

  • EPSS 0.28%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:38:32

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

  • EPSS 0.17%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:40:20

Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).

  • EPSS 0.31%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:38:32

Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function

  • EPSS 0.37%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:40:20

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

  • EPSS 0.14%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:38:32

Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 20.07.2025 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:38:32

In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.

  • EPSS 0.26%
  • Veröffentlicht 04.07.2025 00:00:00
  • Zuletzt bearbeitet 05.06.2026 19:38:32

In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncated input. Specifically, an out-of-bounds read in mbe...