CVE-2018-19608

Source
https://cve.org/CVERecord?id=CVE-2018-19608
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-19608.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-19608
Downstream
Related
Published
2018-12-05T22:29:00.490Z
Modified
2026-04-16T06:15:53.606065620Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.

References

Affected packages

Git / github.com/armmbed/mbedtls

Affected ranges

Type
GIT
Repo
https://github.com/armmbed/mbedtls
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.1.0"
        },
        {
            "fixed": "2.1.17"
        },
        {
            "introduced": "2.7.0"
        },
        {
            "fixed": "2.7.8"
        },
        {
            "introduced": "2.14.0"
        },
        {
            "fixed": "2.14.1"
        }
    ]
}

Affected versions

mbedtls-2.*
mbedtls-2.1.0
mbedtls-2.1.1
mbedtls-2.1.10
mbedtls-2.1.11
mbedtls-2.1.11-rc1
mbedtls-2.1.12
mbedtls-2.1.13
mbedtls-2.1.14
mbedtls-2.1.15
mbedtls-2.1.16
mbedtls-2.1.2
mbedtls-2.1.3
mbedtls-2.1.4
mbedtls-2.1.5
mbedtls-2.1.6
mbedtls-2.1.8
mbedtls-2.1.9
mbedtls-2.1.9-rc1
mbedtls-2.14.0
mbedtls-2.7.0
mbedtls-2.7.1
mbedtls-2.7.2
mbedtls-2.7.2-rc1
mbedtls-2.7.3
mbedtls-2.7.4
mbedtls-2.7.5
mbedtls-2.7.6
mbedtls-2.7.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-19608.json"