Trustedfirmware

Mbed Tls

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.74%
  • Veröffentlicht 03.04.2024 03:15:10
  • Zuletzt bearbeitet 05.06.2026 19:38:32

In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 server via a TLS 3.1 ClientHello.

  • EPSS 0.41%
  • Veröffentlicht 03.04.2024 03:15:10
  • Zuletzt bearbeitet 05.06.2026 19:38:32

An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall back to the TLS 1.2 implementation of the protocol if it is disabled. If the TLS 1.2 implementation was disabled at build time, a...

  • EPSS 0.85%
  • Veröffentlicht 29.03.2024 06:15:07
  • Zuletzt bearbeitet 05.06.2026 19:38:32

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.

  • EPSS 1.12%
  • Veröffentlicht 31.01.2024 08:15:42
  • Zuletzt bearbeitet 05.06.2026 19:38:32

Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().

  • EPSS 0.31%
  • Veröffentlicht 31.01.2024 08:15:42
  • Zuletzt bearbeitet 05.06.2026 19:38:32

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to se...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 21.01.2024 23:15:44
  • Zuletzt bearbeitet 05.06.2026 19:38:32

An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

  • EPSS 1.06%
  • Veröffentlicht 07.10.2023 01:15:10
  • Zuletzt bearbeitet 05.06.2026 19:38:32

Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.

  • EPSS 0.79%
  • Veröffentlicht 07.10.2023 01:15:10
  • Zuletzt bearbeitet 05.06.2026 19:38:32

Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.

  • EPSS 0.16%
  • Veröffentlicht 17.01.2023 21:15:10
  • Zuletzt bearbeitet 05.06.2026 19:38:32

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (...

  • EPSS 1.16%
  • Veröffentlicht 15.12.2022 23:15:10
  • Zuletzt bearbeitet 05.06.2026 19:38:32

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_...