CVE-2024-23170 is a timing side-channel vulnerability affecting RSA private operations in Mbed TLS versions 2.x before 2.28.7 and 3.x before 3.5.2. A local attacker could exploit this flaw by sending numerous messages for decryption, potentially recovering the plaintext. Rated Medium severity (CVSS 5.5), it requires local access and low attack complexity, with a high impact on confidentiality. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.28.7CPE matchmatch criteria | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.5.2CPE matchmatch criteria | cpe:2.3:a:trustedfirmware:mbed_tls:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.