CVE-2018-19608: Medium severity Arm mbed TLS vulnerability
Published Dec 5, 2018
·Updated
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
Affected Software
4 affected components
Arm mbed TLS>=2.1.0<2.1.17
Arm mbed TLS>=2.7.0<2.7.8
Arm mbed TLS>=2.14.0<2.14.1
TrustedFirmware Mbed Tls>=2.14.0<2.14.1
Event History
Dec 5, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-19608?
CVE-2018-19608 is a vulnerability in Arm Mbed TLS before versions 2.14.1, 2.7.8, and 2.1.17 that allows a local unprivileged attacker to recover the plaintext of RSA decryption.
2
What is the severity of CVE-2018-19608?
CVE-2018-19608 has a severity rating of 4.7 (medium).
3
How does CVE-2018-19608 affect Arm Mbed TLS?
CVE-2018-19608 affects Arm Mbed TLS versions before 2.14.1, 2.7.8, and 2.1.17.
4
How can an attacker exploit CVE-2018-19608?
An attacker can exploit CVE-2018-19608 by performing a local unprivileged attack to recover the plaintext of RSA decryption.
5
Is there a fix for CVE-2018-19608?
Yes, the fix for CVE-2018-19608 is available in Arm Mbed TLS versions 2.14.1, 2.7.8, and 2.1.17.