CVE Database
/

CVE-2018-0497

Back to search

CVE-2018-0497

Published: Jul 28, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (with a wrong SHA-384 calculation) for CVE-2013-0169.

VendorProductVersions

n/a

ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14

affected
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now