CVE-2018-0497: Medium severity Arm mbed TLS vulnerability
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (with a wrong SHA-384 calculation) for CVE-2013-0169.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0497?
CVE-2018-0497 is a vulnerability in ARM mbed TLS that allows remote attackers to achieve partial plaintext recovery via a timing-based side-channel attack.
How does CVE-2018-0497 work?
CVE-2018-0497 works by exploiting a timing-based side-channel attack in the CBC based ciphersuite of ARM mbed TLS.
What is the severity of CVE-2018-0497?
CVE-2018-0497 has a severity rating of 5.9, which is classified as medium.
Which version of ARM mbed TLS is affected by CVE-2018-0497?
ARM mbed TLS versions before 2.12.0, 2.7.5, and 2.1.14 are affected by CVE-2018-0497.
How can I fix CVE-2018-0497?
To fix CVE-2018-0497, update ARM mbed TLS to version 2.12.0 or later.