CVE-2020-36424: Medium severity mbed tls vulnerability
An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36424.
What is the severity level of CVE-2020-36424?
The severity level of CVE-2020-36424 is medium.
Which software versions are affected by CVE-2020-36424?
Versions up to exclusive 2.7.17, between inclusive exclusive 2.8.0 and 2.16.8, and between inclusive exclusive 2.17.0 and 2.24.0 of Arm Mbed TLS are affected by CVE-2020-36424.
How can an attacker exploit CVE-2020-36424?
An attacker can exploit CVE-2020-36424 by performing a side-channel attack against the generation of base blinding/unblinding values to recover a private key (for RSA or static Diffie-Hellman).
How can I fix CVE-2020-36424?
To fix CVE-2020-36424, it is recommended to update Arm Mbed TLS to version 2.24.0 or later.