CVE-2020-36423

An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn’t properly consider the case of a hardware accelerator.

Summary:

An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn’t properly consider the case of a hardware accelerator.

Reference Links(if available):

  • https://bugs.gentoo.org/730752
  • https://github.com/ARMmbed/mbedtls/releases/tag/v2.23.0
  • https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.7
  • CVSS Score (if available)

    v2: / MEDIUM

    v3: /

    Links to Exploits(if available)