First published: Wed Mar 15 2023(Updated: )
The armv8_dec_aes_gcm_full() API of Arm AArch64cryptolib before 86065c6 fails to the verify the authentication tag of AES-GCM protected data, leading to a man-in-the-middle attack. This occurs because of an improperly initialized variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arm AArch64cryptolib | <2023-02-20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-26084.
The severity of CVE-2023-26084 is low.
CVE-2023-26084 affects Arm AArch64cryptolib before version 86065c6.
CVE-2023-26084 can result in a man-in-the-middle attack.
To fix CVE-2023-26084, update Arm AArch64cryptolib to version 86065c6 or later.