Vulnerability Description
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arm | Mbed Tls | >= 2.1.0, < 2.1.17 |
Related Weaknesses (CWE)
References
- http://cat.eyalro.net/Third Party Advisory
- https://tls.mbed.org/tech-updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-releaThird Party Advisory
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-Third Party Advisory
- http://cat.eyalro.net/Third Party Advisory
- https://tls.mbed.org/tech-updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-releaThird Party Advisory
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-Third Party Advisory
FAQ
What is CVE-2018-19608?
CVE-2018-19608 is a vulnerability with a CVSS score of 4.7 (MEDIUM). Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
How severe is CVE-2018-19608?
CVE-2018-19608 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19608?
Check the references section above for vendor advisories and patch information. Affected products include: Arm Mbed Tls.