CVE-2021-24119: Medium severity mbed tls vulnerability
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24119?
CVE-2021-24119 is a side-channel vulnerability in base64 PEM file decoding in Trusted Firmware Mbed TLS 2.24.0.
Who is affected by CVE-2021-24119?
Users of ARM mbed TLS 2.24.0 up to 2.26.0 and Fedora 33, Fedora 34, Debian Linux 9.0, and Debian Linux 10.0 are affected.
How can an attacker exploit CVE-2021-24119?
An attacker with system-level access can use controlled-channel and side-channel attacks to obtain information about secret RSA keys.
What is the severity of CVE-2021-24119?
CVE-2021-24119 has a severity rating of 4.9 (medium).
Where can I find more information about CVE-2021-24119?
You can find more information about CVE-2021-24119 at the following references: [Link1], [Link2], [Link3].