CVE-2020-36423: High severity mbed tls vulnerability
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-36423?
CVE-2020-36423 is a vulnerability in Arm Mbed TLS before 2.23.0 that allows a remote attacker to recover plaintext due to a certain Lucky 13 countermeasure not considering the case of a hardware accelerator.
What is the severity of CVE-2020-36423?
CVE-2020-36423 has a severity rating of 7.5 (high).
How does CVE-2020-36423 affect ARM mbed TLS?
CVE-2020-36423 affects ARM mbed TLS versions up to (but not including) 2.23.0.
How can a remote attacker exploit CVE-2020-36423?
A remote attacker can exploit CVE-2020-36423 to recover plaintext due to a certain Lucky 13 countermeasure not considering the case of a hardware accelerator.
How can I fix CVE-2020-36423?
To fix CVE-2020-36423, update to Arm Mbed TLS version 2.23.0 or higher.