Missing Encryption of Sensitive Data in mbed Crypto - CVE-2020-10941

 

Missing Encryption of Sensitive Data in mbed Crypto - CVE-2020-10941

Published: March 24, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34604
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10941
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Arm Mbed TLS before 2.6.15 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.


Affected software

mbed Crypto
Fedora
mbedtls

How to mitigate CVE-2020-10941

Install update from vendor's website.

mbed Crypto - update to 3.1.0
mbedtls - addressed in versions 2.7.16-1.el6, 2.7.16-1.el7, 2.16.7-1.el8, 2.16.7-1.fc31, 2.16.7-1.fc32

External References

Related Security Bulletins