Mbed TLS
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*, +1 more
- < 3.6.4
A NULL pointer dereference vulnerability has been identified in Mbed TLS versions prior to 3.6.4. The issue arises in the `mbedtls_asn1_store_named_data` function, where it can process conflicting data that results in a NULL pointer being dereferenced, despite the length parameter indicating data is present.
Exploitation of this vulnerability leads to a NULL pointer dereference, which can cause a program crash or undefined behavior.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.