Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*"
],
"vendor_product": "arm:mbed_tls",
"extracted_events": [
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.17"
},
{
"introduced": "2.7.0"
},
{
"fixed": "2.7.8"
}
]
}
]
}