Description
Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4236-1 | mbedtls security update |
EUVD |
EUVD-2021-23243 | Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA. |
References
History
Fri, 05 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trustedfirmware
Trustedfirmware mbed Tls |
|
| CPEs | cpe:2.3:a:trustedfirmware:mbed_tls:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Trustedfirmware
Trustedfirmware mbed Tls |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 08 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T19:26:11.739Z
Reserved: 2021-07-12T00:00:00.000Z
Link: CVE-2021-36647
Updated: 2024-08-04T01:01:58.158Z
Status : Modified
Published: 2023-01-17T21:15:10.880
Modified: 2026-06-17T03:58:59.387
Link: CVE-2021-36647
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Debian DLA
EUVD