CVE-2020-36421: Medium severity mbed tls vulnerability
An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-36421?
CVE-2020-36421 is a vulnerability discovered in Arm Mbed TLS before version 2.23.0 that allows the disclosure of an RSA private key used in a secure enclave due to a side channel in modular exponentiation.
How does CVE-2020-36421 affect Arm Mbed TLS?
CVE-2020-36421 affects Arm Mbed TLS versions up to (but not including) 2.23.0 and allows the disclosure of an RSA private key used in a secure enclave.
What is the severity of CVE-2020-36421?
CVE-2020-36421 has a severity level of 5.3 (Medium).
How can I fix CVE-2020-36421?
To fix CVE-2020-36421, update your Arm Mbed TLS installation to version 2.23.0 or later.
Where can I find more information about CVE-2020-36421?
You can find more information about CVE-2020-36421 in the following references: [1] [2] [3]