CVE-2020-36422: Medium severity mbed tls vulnerability
An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtlsecpcheckpubpriv, mbedtlspkparsekey, mbedtlspkparsekeyfile, mbedtlsecpmul, and mbedtlsecpmulrestartable.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36422.
What is the severity of CVE-2020-36422?
The severity of CVE-2020-36422 is medium with a CVSS score of 5.3.
Which software is affected by CVE-2020-36422?
Arm Mbed TLS versions up to and including 2.16.7 and versions between 2.17.0 and 2.23.0, as well as Debian Linux version 10.0, are affected by CVE-2020-36422.
What is the issue with CVE-2020-36422?
CVE-2020-36422 is a side channel vulnerability that allows an attacker to recover an ECC private key through various functions in Arm Mbed TLS.
How can I fix CVE-2020-36422?
To fix CVE-2020-36422, update to a version of Arm Mbed TLS that is later than 2.23.0 or apply the necessary patches provided by the software vendor.