Missing Encryption of Sensitive Data in mbed Crypto - CVE-2020-10941
Published: March 24, 2020 / Updated: August 8, 2020
Vulnerability identifier: #VU34604
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10941
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Arm Mbed TLS before 2.6.15 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.
Affected software
mbed Crypto
Fedora
mbedtls
Fedora
mbedtls
How to mitigate CVE-2020-10941
Install update from vendor's website.
mbed Crypto - update to 3.1.0
mbedtls - addressed in versions 2.7.16-1.el6, 2.7.16-1.el7, 2.16.7-1.el8, 2.16.7-1.fc31, 2.16.7-1.fc32
mbedtls - addressed in versions 2.7.16-1.el6, 2.7.16-1.el7, 2.16.7-1.el8, 2.16.7-1.fc31, 2.16.7-1.fc32
External References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5JPE2HFBDJF3UBT6Q4VWLKNKCVCMX25J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WD6OSOLLAR2AVPJAMGUKWRXN6477IHHV/
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2020-02