CVE-2021-43666: High severity mbed tls vulnerability
Published Mar 24, 2022
·Updated
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtlspkcs12derivation function when an input password's length is 0.
Affected Software
2 affected components
Arm mbed TLS<=3.0.0
Debian Debian Linux=10.0
Event History
Mar 24, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Denial of Service vulnerability in mbed TLS?
The vulnerability ID for this Denial of Service vulnerability in mbed TLS is CVE-2021-43666.
2
What is the severity of CVE-2021-43666?
The severity of CVE-2021-43666 is high with a severity value of 7.5.
3
What is the affected software for CVE-2021-43666?
The affected software for CVE-2021-43666 includes mbed TLS 3.0.0 and earlier as well as Debian Linux 10.0.
4
What is the description of CVE-2021-43666 vulnerability?
CVE-2021-43666 is a Denial of Service vulnerability in mbed TLS that occurs in the mbedtls_pkcs12_derivation function when an input password's length is 0.
5
How can I fix CVE-2021-43666 vulnerability?
To fix CVE-2021-43666 vulnerability, it is recommended to update mbed TLS to version 3.0.1 or later.