Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00308}

epss

{'score': 0.00342}


Tue, 06 May 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Arm
Arm mbed Tls
CPEs cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
Vendors & Products Arm
Arm mbed Tls

Mon, 25 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Mbed
Mbed mbedtls
CPEs cpe:2.3:a:mbed-tls:mbedtls:*:*:*:*:*:*:*:* cpe:2.3:a:mbed:mbedtls:*:*:*:*:*:*:*:*
Vendors & Products Mbed-tls
Mbed-tls mbedtls
Mbed
Mbed mbedtls

Thu, 17 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mbed-tls
Mbed-tls mbedtls
Weaknesses CWE-787
CPEs cpe:2.3:a:mbed-tls:mbedtls:*:*:*:*:*:*:*:*
Vendors & Products Mbed-tls
Mbed-tls mbedtls
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 19:45:00 +0000

Type Values Removed Values Added
Description Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-25T20:53:41.370Z

Reserved: 2024-10-13T00:00:00

Link: CVE-2024-49195

cve-icon Vulnrichment

Updated: 2024-10-17T17:23:41.588Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T20:15:21.950

Modified: 2025-05-06T18:01:24.893

Link: CVE-2024-49195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.