PT-2024-1658 · Mbed Tls+3 · Mbed Tls+3

·

CVE-2024-23170

·

Published

2024-01-10

·

Updated

2026-08-25

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mbed TLS versions 2.x before 2.28.7 Mbed TLS versions 3.x before 3.5.2
Description A timing side channel in RSA private operations could allow a local attacker to recover the plaintext by sending a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario. This side channel could be exploited by a remote attacker to gain access to confidential information.
Recommendations For Mbed TLS versions 2.x before 2.28.7, update to version 2.28.7 or later to resolve the issue. For Mbed TLS versions 3.x before 3.5.2, update to version 3.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to RSA private operations until a patch is available.

Exploit

Fix

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15509
ALT-PU-2025-10462
AZL-47697
BDU:2024-01340
CVE-2024-23170
OPENSUSE-SU-2024:0037-1
OPENSUSE-SU-2024:13639-1
OPENSUSE-SU-2024:13640-1

Affected Products

Alt Linux
Astra Linux
Debian
Mbed Tls