Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ARM mbed TLS加密问题漏洞
Vulnerability Description
ARM mbed TLS是英国ARM公司的一款为mbed产品提供安全通讯和加密功能的产品。 Mbed TLS 2.28.0之前版本和 3.0版本存在安全漏洞,该漏洞源于psa_cipher_generate_iv 和 psa_cipher_encrypt允许策略绕过或基于oracle的解密,可被不受信任的应用程序访问。
CVSS Information
N/A
Vulnerability Type
N/A