CVE-2024-23170: Medium severity Microsoft cbl2 hvloader 1.0.1-5 vulnerability
Published Jan 31, 2024
·Updated
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations.
Affected Software
5 affected componentsFixes available
Microsoft cbl2 hvloader 1.0.1-5
Microsoft cbl2 hvloader 1.0.1-6
Microsoft cbl2 hvloader 1.0.1-5
Arm mbed TLS>=2.0.0<2.28.7
TrustedFirmware Mbed Tls>=3.0.0<3.5.2
Event History
Jan 31, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Nov 28, 2024
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
SeverityAffected Software
Updated
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-23170?
CVE-2024-23170 is classified as a high severity vulnerability due to its potential for enabling plaintext recovery through a timing side channel.
2
How do I fix CVE-2024-23170?
To fix CVE-2024-23170, upgrade Mbed TLS to versions 2.28.7 or 3.5.2 or later.
3
Which versions of Mbed TLS are affected by CVE-2024-23170?
CVE-2024-23170 affects Mbed TLS versions before 2.28.7 and 3.x versions before 3.5.2.
4
Can CVE-2024-23170 be exploited remotely?
No, CVE-2024-23170 requires a local attacker to exploit the vulnerability through sending numerous decryption requests.
5
What are the consequences of exploiting CVE-2024-23170?
Exploiting CVE-2024-23170 could allow a local attacker to recover sensitive plaintext information from RSA private operations.