Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mbed TLS 加密问题漏洞
Vulnerability Description
Mbed TLS是一个开源、可移植、易于使用、可读且灵活的 SSL 库。 Mbed TLS 3.0.0之前版本存在安全漏洞,该漏洞源于lignum.c的mbedtls_mpi_exp_mod()函数中使用危险的加密算法。攻击者利用该漏洞访问敏感信息,从而恢复RSA中使用的私钥。
CVSS Information
N/A
Vulnerability Type
N/A