Description
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2826-1 | mbedtls security update |
Debian DLA |
DLA-3249-1 | mbedtls security update |
Debian DLA |
DLA-4236-1 | mbedtls security update |
EUVD |
EUVD-2021-11034 | In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX. |
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T19:25:39.621Z
Reserved: 2021-01-14T00:00:00.000Z
Link: CVE-2021-24119
No data.
Status : Modified
Published: 2021-07-14T13:15:08.100
Modified: 2025-11-03T20:15:45.783
Link: CVE-2021-24119
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD