CVE-2020-16150: Medium severity mbed tls vulnerability
A Lucky 13 timing side channel in mbedtlsssldecryptbuf in library/sslmsg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-16150?
CVE-2020-16150 is a Lucky 13 timing side channel vulnerability in mbedtls_ssl_decrypt_buf in Trusted Firmware Mbed TLS through 2.23.0.
How does CVE-2020-16150 affect the ARM mbed TLS library?
CVE-2020-16150 affects the ARM mbed TLS library versions up to 2.7.17, between 2.8.0 and 2.16.8, and between 2.17.0 and 2.24.0.
What is the severity of CVE-2020-16150?
CVE-2020-16150 has a severity of 5.5 (medium).
How can an attacker exploit CVE-2020-16150?
An attacker can exploit CVE-2020-16150 to recover secret key information through a Lucky 13 timing side channel in CBC mode.
How can I mitigate CVE-2020-16150?
To mitigate CVE-2020-16150, update to a version of the ARM mbed TLS library above 2.24.0 or apply the necessary patches provided by the vendor.