CVE-2024-45157: Medium severity TrustedFirmware Mbed Tls vulnerability
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLSPSAHMACDRBGMDTYPE does not cause the PSA subsystem to use HMACDRBG: it uses HMACDRBG only when MBEDTLSPSACRYPTOEXTERNALRNG and MBEDTLSCTRDRBGC are disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45157?
CVE-2024-45157 is considered a high-severity vulnerability as it affects the cryptographic functionality of Mbed TLS.
How do I fix CVE-2024-45157?
To mitigate CVE-2024-45157, update Mbed TLS to version 2.28.10 or 3.6.1 or later.
Which versions of Mbed TLS are affected by CVE-2024-45157?
CVE-2024-45157 affects Mbed TLS versions before 2.28.9 and 3.x versions before 3.6.1.
What functionality is impacted by CVE-2024-45157?
CVE-2024-45157 impacts the correct use of user-selected algorithms in the PSA subsystem of Mbed TLS.
Is there a workaround for CVE-2024-45157?
There is no documented workaround for CVE-2024-45157; updating to a patched version is recommended.